#VU22765 Permissions, Privileges, and Access Controls in Email Subscribers & Newsletters
Published: November 14, 2019
Email Subscribers & Newsletters
icegram
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insecure permission on dashboard and settings. A remote authenticated user with the "edit_post" capability can view and modify settings, such as send new campaigns, view subscriber information, add new users, change settings, and more.