Show filters
44 Total Results
Displaying 41-44 of 44
Sort by:
Attacker Value
Unknown

CVE-2019-13569

Disclosure Date: July 19, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
0
Attacker Value
Unknown

CVE-2019-19985

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Attacker Value
Unknown

CVE-2018-0602

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-6015

Disclosure Date: January 26, 2018 (last updated November 26, 2024)
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
0