Vulnerability Details: Authenticated Persistent Cross-Site Scripting (XSS) in Email Subscribers & Newsletters
One of the changelog entries for the latest version of Email Subscribers & Newsletters is “Fix: Fixed Vulnerability”. Looking at the changes made in that version at first glance, we thought it might be fixing a vulnerability we disclosed in April, but that wasn’t the case. What we subsequently found is that what appears to be an attempt to fix a vulnerability hadn’t been successful, due to two different security failures. While one of those failures would be somewhat understandable normally, the developer markets their plugins with this claim:
...
This post provides insights on a vulnerability in the WordPress plugin Email Subscribers & Newsletters not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.
If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.
For existing customers, please log in to your account to view the rest of the contents of the post.