Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D3F027C6-3006-45F2-AA5D-C8B9BB602C66
HistoryJul 18, 2020 - 12:00 a.m.

Email Subscribers & Newsletters < 4.5.1 - Authenticated SQL injection in es_newsletters_settings_callback()

2020-07-1800:00:00
wpscan.com
6

0.001 Low

EPSS

Percentile

41.8%

An authenticated high privilege attacker could exploit this issue an gain access to the DBMS.

PoC

https://github.com/tenable/poc/blob/master/WordPress/plugins/Icegram/email_subscribers_and_newsletters/sqli_info_disclosure_poc.py

CPENameOperatorVersion
email-subscriberslt4.5.1

0.001 Low

EPSS

Percentile

41.8%

Related for WPVDB-ID:D3F027C6-3006-45F2-AA5D-C8B9BB602C66