Tuesday, October 15, 2024
HomeInternetMultiple Vulnerabilities Discovered in Wordpress Email Subscribers & Newsletters Plugin that has...

Multiple Vulnerabilities Discovered in WordPress Email Subscribers & Newsletters Plugin that has 100,000+ Installs

Published on

Malware protection

The Email Subscribers & Newsletters is a WordPress newsletter plugin used to send post notifications, send broadcasts. It can be integrated with Mailchimp and the plugin has more than 100,000+ active installs.

Wordfence Threat Intelligence team has discovered multiple vulnerabilities in the plugin that allows attackers to launch various attacks targeting vulnerable installations.

Vulnerabilities Detected – Email Subscribers & Newsletters

  • Information Disclosure
  • Blind SQL Injection in the INSERT statement
  • Insecure Permissions
  • Cross-Site Request Forgery on Settings
  • Subscriber can send Email from admin Dashboard
  • Unauthenticated Option Creation

Information Disclosure

The plugin has an option to export all the subscribers into a single CSV file that contains the details provided by subscribers such as first names, last names, email addresses, mailing lists.

- Advertisement - SIEM as a Service

These details can be downloaded only by the server admin, there is a flaw in plugin version 4.2.2 which allows unauthenticated users to export the data.

The vulnerability received CVSS v3.0 Score: 5.8(Medium) and fixed with version 4.2.3.

Blind SQL Injection

The plugin has functionality tracked ‘open’ actions to check for several users opening the email, but there is a flaw in the plugin which allows “SQL statements to be passed to the database in the hash parameter creating a blind SQL injection vulnerability,” reads Wordfence blog post.

The vulnerability received CVSS v3.0 Score: 8.3(high) and it has been fixed with version 4.3.1.

Insecure Permissions

With the admin dashboard, the Email Subscribers & Newsletter plugin contains options such as settings, audience information, campaign information, forms, and more.

These options can be accessed by any user with the permission edit_post, the contributor user, WordPress themes and plugins have this option.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Cross-Site Request Forgery

The plugin has no nonce checks to see whether the request coming from the admin session, this allows attackers to modify settings via CSRF.

The vulnerability received CVSS v3.0 Score: 6.3(Medium) and it has been fixed with version 4.2.3.

Send Test Emails from the Administrative Dashboard

The plugin contains options to send the test to verify the configurations, unfortunately, there is a vulnerability with the plugin that allows unauthenticated users to send the test mails.

The vulnerability received CVSS v3.0 Score: 4.3(Medium) and it has been fixed with version 4.2.3.

Unauthenticated Option Creation

The Email Subscribers & Newsletters plugin has an onboarding option that can be skipped after installation, if it is skipped then “it creates a new option in the database and saves the value as yes.”

“Unfortunately, there was no access control for this feature so any unauthenticated user could create this option in the database, which could be appended with any value.”

The vulnerabilities were reported to the developer team by Wordfence on October 14th, 2019, on October 23rd, 2019 initial patch was released and a final patch released on November 13th, 2019. Users are recommended to update with the latest version 4.3.1.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Splunk Enterprise Vulnerabilities let Attackers Execute Remote Code

Splunk has disclosed multiple vulnerabilities affecting its Enterprise product, which could allow attackers to...

OilRig Hackers Exploiting Microsoft Exchange Server To Steal Login Details

Earth Simnavaz, an Iranian state-sponsored cyber espionage group, has recently intensified its attacks on...

CoreWarrior Malware Attacking Windows Machines From Dozens Of IP Address

Researchers recently analyzed a CoreWarrior malware sample, which spreads aggressively by creating numerous copies...

TrickMo Malware Targets Android Devices to Steal Unlock Patterns and PINs

The recent discovery of the TrickMo Banking Trojan variant by Cleafy has prompted further...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Unauthenticated RCE in WordPress Plugin Exposes 100,000 WordPress Sites

A critical vulnerability has been discovered in the GiveWP plugin, a popular WordPress donation...

Hackers Actively Exploiting WordPress Plugin Arbitrary File Upload Vulnerability

Hackers have been actively exploiting a critical vulnerability in the WordPress plugin 简数采集器 (Keydatas)....

SocGholish Malware Attacking Windows Users Using Fake Browser Update

The SocGholish downloader has been in operation since 2017 and it is still evolving....