Description
WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions which can cause a loss of confidentiality, integrity, and availability. WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce version 5.7.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.7.20 or latest
References
Related Vulnerabilities
WordPress Plugin WP Server Health Stats Malicious Code (1.7.6)
PHP Use of Uninitialized Resource Vulnerability (CVE-2015-3414)
Drupal Core 4.7.x Denial of Service (4.7.0 - 4.7.4)
e107 Other Vulnerability (CVE-2004-2262)
WordPress Plugin YouSayToo auto-publishing 'submit' Parameter Cross-Site Scripting (1.0.1)