Vulnerability record · CVE-2019-20361 · published 8 January 2020
CVE-2019-20361: WordPress Email Subscribers & Newsletters plugin blind SQL injection
Icegram · Email Subscribers \& Newsletters
The Email Subscribers & Newsletters WordPress plugin before 4.3.1 passes the hash parameter to the database without proper sanitization, allowing blind SQL injection. This is a critical, remotely reachable flaw in a widely deployed plugin, so unauthenticated attackers can extract or manipulate database contents.
Description
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and very high EPSS make this an urgent patch target.
What it is
The Email Subscribers & Newsletters WordPress plugin before 4.3.1 passes the hash parameter to the database without proper sanitization, allowing blind SQL injection. This is a critical, remotely reachable flaw in a widely deployed plugin, so unauthenticated attackers can extract or manipulate database contents.
Impact
An attacker can read arbitrary data from the WordPress database, including user credentials and subscriber records, and may alter or delete data depending on database privileges.
Attack surface
Reached over the network through the plugin's hash parameter; the CVSS vector shows no privileges or user interaction required, so it is unauthenticated and remotely exploitable.
Exploitation
CISA KEV does not list it, but EPSS is 0.8511 (99.7th percentile) and references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Update the Email Subscribers & Newsletters plugin to version 4.3.1 or later immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Restrict access to WordPress admin and plugin endpoints via WAF rules or IP allowlisting where feasible.
- Audit database accounts used by WordPress for least privilege and rotate credentials if compromise is suspected.
- Review logs for requests containing SQL syntax in the hash parameter.
Detection
- Search web server and WAF logs for requests with SQL keywords or comment sequences in the hash parameter.
- Monitor for unusual database queries or errors originating from the plugin's endpoints.
- Check for unexpected changes to WordPress users, options, or subscriber tables.
- Use file integrity monitoring to detect modified plugin files or dropped webshells.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158568/WordPress-Email-Subscribers-And-Newsletters-4.2.2-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://wpvulndb.com/vulnerabilities/9947 | Third Party Advisory |
| https://www.wordfence.com/blog/2019/11/multiple-vulnerabilities-patched-in-email-subscribers-newsletters-plugin/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/158568/WordPress-Email-Subscribers-And-Newsletters-4.2.2-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://wpvulndb.com/vulnerabilities/9947 | Third Party Advisory |
| https://www.wordfence.com/blog/2019/11/multiple-vulnerabilities-patched-in-email-subscribers-newsletters-plugin/ | ExploitThird Party Advisory |
Track CVE-2019-20361 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-20361), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.