CVE-2018-6015

CVE-2018-6015

An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.

Source: CVE-2018-6015

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다