← Back to browse · API

CVE-2019-19985

Severity
MEDIUM
CVSS
5.8
EPSS
0.71399
Risk score
48.19
CISA KEV
No
PoC
No
Published
2019-12-26
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-9573, GHSA-862M-V43M-WWR6
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-9573

Description

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

References