Vulnerabilities > Icegram > Email Subscribers Newsletters > 3.4.10

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2019-19982 Improper Authentication vulnerability in Icegram Email Subscribers & Newsletters
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation.
network
low complexity
icegram CWE-287
5.0
2019-12-26 CVE-2019-19981 Cross-Site Request Forgery (CSRF) vulnerability in Icegram Email Subscribers & Newsletters
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
network
icegram CWE-352
4.3
2019-12-26 CVE-2019-19980 Unspecified vulnerability in Icegram Email Subscribers & Newsletters
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator.
network
low complexity
icegram
4.0
2019-07-19 CVE-2019-13569 SQL Injection vulnerability in Icegram Email Subscribers & Newsletters
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress.
network
low complexity
icegram CWE-89
critical
10.0