Description
WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions which can cause a loss of confidentiality, integrity, and availability. WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce version 5.7.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.7.20 or latest
References
Related Vulnerabilities
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.19)
WordPress Plugin Simple Ads Manager Arbitrary File Upload (2.5.94)
WordPress Plugin AStickyPostOrderER Cross-Site Scripting (0.3.1)
WordPress Plugin WP-Ban Cross-Site Scripting (1.69)
TYPO3 Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-26228)