CVE-2019-20361: Icegram Email Subscribers & Newsletters
Critical severity, CVSS 9.8. EPSS: 85.1% chance of exploitation in the next 30 days.
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
Affected products
- Icegram Email Subscribers & Newsletters: before 4.3.1 (fixed in 4.3.1)
Published 2020-01-08. Last modified 2026-06-17.