vendor:
Email Subscribers & Newsletters
by:
ThreatPress Security
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Email Subscribers & Newsletters
Affected Version From: 3.4.7
Affected Version To: 3.4.7
Patch Exists: YES
Related CWE: N/A
CPE: a:icegram:email_subscribers_&_newsletters
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress 4.9.2
2018
WordPress Plugin Email Subscribers & Newsletters 3.4.7 – Information Disclosure
Email Subscribers & Newsletters, a popular WordPress plugin, has just fixed the vulnerability that allows an unauthenticated user to download the entire subscriber list with names and e-mail addresses.
Mitigation:
Update to the latest version of the plugin.