Mail Subscribe List <= 2.1.3 - Cross-Site Request Forgery

2022-05-26 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 2.1.4
Affected PluginMail Subscribe List
Affected Version< 2.1.4
CVSS8.8High
CVECVE-2022-1603
View all Mail Subscribe List vulnerabilities

Vulnerability Overview

The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list

Technical Analysis

REMEDIATION: Update to version 2.1.4, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C