Monday, May 5, 2025
HomeInternetMultiple Vulnerabilities Discovered in Wordpress Email Subscribers & Newsletters Plugin that has...

Multiple Vulnerabilities Discovered in WordPress Email Subscribers & Newsletters Plugin that has 100,000+ Installs

Published on

SIEM as a Service

Follow Us on Google News

The Email Subscribers & Newsletters is a WordPress newsletter plugin used to send post notifications, send broadcasts. It can be integrated with Mailchimp and the plugin has more than 100,000+ active installs.

Wordfence Threat Intelligence team has discovered multiple vulnerabilities in the plugin that allows attackers to launch various attacks targeting vulnerable installations.

Vulnerabilities Detected – Email Subscribers & Newsletters

  • Information Disclosure
  • Blind SQL Injection in the INSERT statement
  • Insecure Permissions
  • Cross-Site Request Forgery on Settings
  • Subscriber can send Email from admin Dashboard
  • Unauthenticated Option Creation

Information Disclosure

The plugin has an option to export all the subscribers into a single CSV file that contains the details provided by subscribers such as first names, last names, email addresses, mailing lists.

- Advertisement - Google News

These details can be downloaded only by the server admin, there is a flaw in plugin version 4.2.2 which allows unauthenticated users to export the data.

The vulnerability received CVSS v3.0 Score: 5.8(Medium) and fixed with version 4.2.3.

Blind SQL Injection

The plugin has functionality tracked ‘open’ actions to check for several users opening the email, but there is a flaw in the plugin which allows “SQL statements to be passed to the database in the hash parameter creating a blind SQL injection vulnerability,” reads Wordfence blog post.

The vulnerability received CVSS v3.0 Score: 8.3(high) and it has been fixed with version 4.3.1.

Insecure Permissions

With the admin dashboard, the Email Subscribers & Newsletter plugin contains options such as settings, audience information, campaign information, forms, and more.

These options can be accessed by any user with the permission edit_post, the contributor user, WordPress themes and plugins have this option.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Cross-Site Request Forgery

The plugin has no nonce checks to see whether the request coming from the admin session, this allows attackers to modify settings via CSRF.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Send Test Emails from the Administrative Dashboard

The plugin contains options to send the test to verify the configurations, unfortunately, there is a vulnerability with the plugin that allows unauthenticated users to send the test mails.

The vulnerability received CVSS v3.0 Score: 4.3(Medium) and it has been fixed with version 4.2.3.

Unauthenticated Option Creation

The Email Subscribers & Newsletters plugin has an onboarding option that can be skipped after installation, if it is skipped then “it creates a new option in the database and saves the value as yes.”

“Unfortunately, there was no access control for this feature so any unauthenticated user could create this option in the database, which could be appended with any value.”

The vulnerabilities were reported to the developer team by Wordfence on October 14th, 2019, on October 23rd, 2019 initial patch was released and a final patch released on November 13th, 2019. Users are recommended to update with the latest version 4.3.1.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Gunra Ransomware’s Double‑Extortion Playbook and Global Impact

Gunra Ransomware, has surfaced as a formidable threat in April 2025, targeting Windows systems...

Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers

Cybersecurity firm Sansec has uncovered a sophisticated supply chain attack that has compromised 21...

Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware

The financially motivated threat group Venom Spider, also tracked as TA4557, has shifted its...

RomCom RAT Targets UK Organizations Through Compromised Customer Feedback Portals

The Russian-based threat group RomCom, also known as Storm-0978, Tropical Scorpius, and Void Rabisu,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

New WordPress Malware Disguised as Anti-Malware Plugin Takes Full Control of Websites

The Wordfence Threat Intelligence team has identified a new strain of WordPress malware that...

WordPress Ad-Fraud Plugins Trigger Massive 1.4 Billion Daily Ad Requests

Cybersecurity researchers have uncovered a sprawling ad-fraud operation exploiting WordPress plugins to trigger over...

Over 100,000 WordPress Plugin Vulnerability Exploited Just 4 Hours After Disclosure

Over 100,000 WordPress websites have been exposed to a critical security vulnerability, following the...