Wednesday, January 15, 2025
HomeInternetMultiple Vulnerabilities Discovered in Wordpress Email Subscribers & Newsletters Plugin that has...

Multiple Vulnerabilities Discovered in WordPress Email Subscribers & Newsletters Plugin that has 100,000+ Installs

Published on

The Email Subscribers & Newsletters is a WordPress newsletter plugin used to send post notifications, send broadcasts. It can be integrated with Mailchimp and the plugin has more than 100,000+ active installs.

Wordfence Threat Intelligence team has discovered multiple vulnerabilities in the plugin that allows attackers to launch various attacks targeting vulnerable installations.

Vulnerabilities Detected – Email Subscribers & Newsletters

  • Information Disclosure
  • Blind SQL Injection in the INSERT statement
  • Insecure Permissions
  • Cross-Site Request Forgery on Settings
  • Subscriber can send Email from admin Dashboard
  • Unauthenticated Option Creation

Information Disclosure

The plugin has an option to export all the subscribers into a single CSV file that contains the details provided by subscribers such as first names, last names, email addresses, mailing lists.

These details can be downloaded only by the server admin, there is a flaw in plugin version 4.2.2 which allows unauthenticated users to export the data.

The vulnerability received CVSS v3.0 Score: 5.8(Medium) and fixed with version 4.2.3.

Blind SQL Injection

The plugin has functionality tracked ‘open’ actions to check for several users opening the email, but there is a flaw in the plugin which allows “SQL statements to be passed to the database in the hash parameter creating a blind SQL injection vulnerability,” reads Wordfence blog post.

The vulnerability received CVSS v3.0 Score: 8.3(high) and it has been fixed with version 4.3.1.

Insecure Permissions

With the admin dashboard, the Email Subscribers & Newsletter plugin contains options such as settings, audience information, campaign information, forms, and more.

These options can be accessed by any user with the permission edit_post, the contributor user, WordPress themes and plugins have this option.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Cross-Site Request Forgery

The plugin has no nonce checks to see whether the request coming from the admin session, this allows attackers to modify settings via CSRF.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Send Test Emails from the Administrative Dashboard

The plugin contains options to send the test to verify the configurations, unfortunately, there is a vulnerability with the plugin that allows unauthenticated users to send the test mails.

The vulnerability received CVSS v3.0 Score: 4.3(Medium) and it has been fixed with version 4.2.3.

Unauthenticated Option Creation

The Email Subscribers & Newsletters plugin has an onboarding option that can be skipped after installation, if it is skipped then “it creates a new option in the database and saves the value as yes.”

“Unfortunately, there was no access control for this feature so any unauthenticated user could create this option in the database, which could be appended with any value.”

The vulnerabilities were reported to the developer team by Wordfence on October 14th, 2019, on October 23rd, 2019 initial patch was released and a final patch released on November 13th, 2019. Users are recommended to update with the latest version 4.3.1.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Aembit Announces Speaker Lineup for the Inaugural NHIcon

Aembit, the non-human identity and access management (IAM) company, unveiled the full agenda for...

Sweet Security Introduces Patent-Pending LLM-Powered Detection Engine, Reducing Cloud Detection Noise to 0.04%

Sweet Security, a leader in cloud runtime detection and response, today announced the launch...

ShadowSyndicate Hackers Added RansomHub Ransomware to their Arsenal

ShadowSyndicate is a prolific threat actor that has been active since July 2022, collaborated...

5,000 WordPress Sites Hacked in New WP3.XYZ Malware Attack

Widespread malware campaigns detected by side crawlers exploit vulnerabilities on multiple websites where the...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Credit Card Skimmer Hits WordPress Checkout Pages, Stealing Payment Data

Researchers analyzed a new stealthy credit card skimmer that targets WordPress checkout pages by...

Is this Website Safe: How to Check Website Safety – 2025

is this website safe? In this digital world, Check a website is safe is...

New WordPress Plugin That Weaponizes Legit Sites To Steal Customer Payment Data

Cybercriminals have developed PhishWP, a malicious WordPress plugin, to facilitate sophisticated phishing attacks, which...