#VU31679 SQL injection in Email Subscribers & Newsletters - CVE-2020-5768
Published: July 20, 2020
Email Subscribers & Newsletters
icegram
Description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "es_newsletters_settings_callback()" function in "class-es-newsletters.php". A remote administrator can send a specially crafted request and disclose potentially sensitive information such as value of database fields.