S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-19985 Scanner

CVE-2019-19985 scanner - Unauthenticated File Download vulnerability in Email Subscribers & Newsletters plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-19985
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Email Subscribers & Newsletters plugin is a useful tool available on the WordPress platform for bloggers and website owners to connect with their subscribers through email. This plugin allows users to create and send newsletters to their subscribers, as well as monitor the performance of their email campaigns. Users can also customize the design of their emails, schedule them, and manage their subscribers.

Unfortunately, the plugin had a serious vulnerability, known as CVE-2019-19985, which allowed unauthenticated file download with user information disclosure. This vulnerability could be exploited by an attacker who could potentially download sensitive user information, including email addresses, names, and other personal data without any authentication. The vulnerability could also be exploited to gain unauthorized access to the website's backend, allowing an attacker to install malware or compromise the website.

When exploited, CVE-2019-19985 could lead to severe consequences. The attacker could potentially steal confidential data and use it for malicious purposes, such as identity theft or spamming unsuspecting victims. The vulnerability could also lead to reputational damage for the website and its owner, as users may lose trust in the website's security and credibility.

Thanks to the Pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive vulnerability assessment that helps users identify potential threats and vulnerabilities in their websites and applications. With this tool, website owners can stay one step ahead of attackers and protect their digital assets effortlessly.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of the Email Subscribers & Newsletters plugin should take the following precautions:

  • Update to the latest version of the plugin, which has patched the vulnerability.
  • Avoid using outdated or unsupported versions of WordPress and its plugins.
  • Use strong and unique passwords for all accounts associated with the website.
  • Enable two-factor authentication to add an additional layer of security to the login process.
  • Regularly monitor the website for any unusual activity or suspicious behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.