
Cloud Vulnerability DB
A community-led vulnerabilities database
The ENL Newsletter WordPress plugin through version 1.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability. The plugin lacks CSRF checks in certain functionalities, which was discovered and reported by Bob Matyas. The vulnerability was publicly disclosed on April 5, 2024 (WPScan).
The vulnerability stems from missing CSRF protection mechanisms in the plugin's campaign management functionality. This security flaw allows attackers to execute unauthorized actions by making logged-in administrators unknowingly delete arbitrary campaigns. The vulnerability has been assigned a CVSS score of 5.7 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N, indicating that it requires user interaction and logged-in admin status to exploit (WPScan).
If successfully exploited, an attacker can trick authenticated administrators into deleting campaign data without their knowledge or consent. This could result in the loss of important campaign information and disrupt the newsletter management system (WPScan).
The vulnerability can be exploited by crafting a malicious URL in the format: http://example.com/wp-admin/admin.php?page=enl-campaigns&action=campaign-delete&id=<ID>, where <ID> represents a valid campaign identifier. When an authenticated administrator visits this URL, it will trigger the unintended deletion of the specified campaign (WPScan).
Currently, there is no known fix available for this vulnerability. Users of the ENL Newsletter plugin should exercise caution when clicking on links while logged in as an administrator (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."