HIGH

CVE-2022-0439

CVSS v3

8.8

HIGH

EPSS Score

10.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

Technical details

Published
3/7/2022

Frequently asked questions

What is CVE-2022-0439?

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

Is CVE-2022-0439 actively exploited?

Active exploitation of CVE-2022-0439 has not been confirmed. The EPSS score is 10.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0439?

CVE-2022-0439 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-0439 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.