Email Subscribers & Newsletters <= 4.2.2 - Missing Authorization to Test Email
2019-11-13 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 4.2.3
Affected PluginEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
Affected Version
<= 4.2.2CVSS4.3Medium
CVE
CVE-2019-19980Vulnerability Overview
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.
Technical Analysis
REMEDIATION: Update to version 4.2.3, or a newer patched version --- IDENTIFIER: CWE-305 (Authentication Bypass by Primary Weakness) The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C