Friday, May 23, 2025
HomeInternetMultiple Vulnerabilities Discovered in Wordpress Email Subscribers & Newsletters Plugin that has...

Multiple Vulnerabilities Discovered in WordPress Email Subscribers & Newsletters Plugin that has 100,000+ Installs

Published on

SIEM as a Service

Follow Us on Google News

The Email Subscribers & Newsletters is a WordPress newsletter plugin used to send post notifications, send broadcasts. It can be integrated with Mailchimp and the plugin has more than 100,000+ active installs.

Wordfence Threat Intelligence team has discovered multiple vulnerabilities in the plugin that allows attackers to launch various attacks targeting vulnerable installations.

Vulnerabilities Detected – Email Subscribers & Newsletters

  • Information Disclosure
  • Blind SQL Injection in the INSERT statement
  • Insecure Permissions
  • Cross-Site Request Forgery on Settings
  • Subscriber can send Email from admin Dashboard
  • Unauthenticated Option Creation

Information Disclosure

The plugin has an option to export all the subscribers into a single CSV file that contains the details provided by subscribers such as first names, last names, email addresses, mailing lists.

- Advertisement - Google News

These details can be downloaded only by the server admin, there is a flaw in plugin version 4.2.2 which allows unauthenticated users to export the data.

The vulnerability received CVSS v3.0 Score: 5.8(Medium) and fixed with version 4.2.3.

Blind SQL Injection

The plugin has functionality tracked ‘open’ actions to check for several users opening the email, but there is a flaw in the plugin which allows “SQL statements to be passed to the database in the hash parameter creating a blind SQL injection vulnerability,” reads Wordfence blog post.

The vulnerability received CVSS v3.0 Score: 8.3(high) and it has been fixed with version 4.3.1.

Insecure Permissions

With the admin dashboard, the Email Subscribers & Newsletter plugin contains options such as settings, audience information, campaign information, forms, and more.

These options can be accessed by any user with the permission edit_post, the contributor user, WordPress themes and plugins have this option.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Cross-Site Request Forgery

The plugin has no nonce checks to see whether the request coming from the admin session, this allows attackers to modify settings via CSRF.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Send Test Emails from the Administrative Dashboard

The plugin contains options to send the test to verify the configurations, unfortunately, there is a vulnerability with the plugin that allows unauthenticated users to send the test mails.

The vulnerability received CVSS v3.0 Score: 4.3(Medium) and it has been fixed with version 4.2.3.

Unauthenticated Option Creation

The Email Subscribers & Newsletters plugin has an onboarding option that can be skipped after installation, if it is skipped then “it creates a new option in the database and saves the value as yes.”

“Unfortunately, there was no access control for this feature so any unauthenticated user could create this option in the database, which could be appended with any value.”

The vulnerabilities were reported to the developer team by Wordfence on October 14th, 2019, on October 23rd, 2019 initial patch was released and a final patch released on November 13th, 2019. Users are recommended to update with the latest version 4.3.1.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

CefSharp Enumeration Tool Identifies Critical Security Issues in .NET Desktop Applications

Cybersecurity researchers and red teamers, a newly released tool named CefEnum is shedding light...

Russian Hackers Exploit Oracle Cloud Infrastructure to Target Scaleway Object Storage

Russian threat actors have been leveraging trusted cloud infrastructure platforms like Oracle Cloud Infrastructure...

Critical Vulnerability in Netwrix Password Manager Enables Authenticated Remote Code Execution

A critical security vulnerability has been discovered in Netwrix Password Secure, a widely used...

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

Cisco Talos has uncovered active exploitation of a zero-day remote-code-execution vulnerability, identified as CVE-2025-0994,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Security Flaw in WordPress Plugin Puts 22,000 Websites at Risk of Cyber Attacks

Critical security vulnerability has been discovered in Motors, a popular WordPress theme with over...

WordPress Plugin Flaw Puts 22,000 Websites at Risk of Cyber Attacks

A severe security flaw has been uncovered in the Motors WordPress theme, a popular...

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...