CVSS v3
9.8
CRITICAL
EPSS Score
31.1%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
Active exploitation of CVE-2019-20361 has not been confirmed. The EPSS score is 31.1%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2019-20361 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).