← Vulnerability feed

Vulnerability record · CVE-2019-20361 · published 8 January 2020

CVE-2019-20361: WordPress Email Subscribers & Newsletters plugin blind SQL injection

Icegram · Email Subscribers \& Newsletters

The Email Subscribers & Newsletters WordPress plugin before 4.3.1 passes the hash parameter to the database without proper sanitization, allowing blind SQL injection. This is a critical, remotely reachable flaw in a widely deployed plugin, so unauthenticated attackers can extract or manipulate database contents.

9.8 CVSS 3.1 Critical EPSS 85% · top 0.3% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and very high EPSS make this an urgent patch target.

What it is

The Email Subscribers & Newsletters WordPress plugin before 4.3.1 passes the hash parameter to the database without proper sanitization, allowing blind SQL injection. This is a critical, remotely reachable flaw in a widely deployed plugin, so unauthenticated attackers can extract or manipulate database contents.

Impact

An attacker can read arbitrary data from the WordPress database, including user credentials and subscriber records, and may alter or delete data depending on database privileges.

Attack surface

Reached over the network through the plugin's hash parameter; the CVSS vector shows no privileges or user interaction required, so it is unauthenticated and remotely exploitable.

Exploitation

CISA KEV does not list it, but EPSS is 0.8511 (99.7th percentile) and references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Update the Email Subscribers & Newsletters plugin to version 4.3.1 or later immediately.
  • If patching is not possible, disable or remove the plugin until it can be updated.
  • Restrict access to WordPress admin and plugin endpoints via WAF rules or IP allowlisting where feasible.
  • Audit database accounts used by WordPress for least privilege and rotate credentials if compromise is suspected.
  • Review logs for requests containing SQL syntax in the hash parameter.

Detection

  • Search web server and WAF logs for requests with SQL keywords or comment sequences in the hash parameter.
  • Monitor for unusual database queries or errors originating from the plugin's endpoints.
  • Check for unexpected changes to WordPress users, options, or subscriber tables.
  • Use file integrity monitoring to detect modified plugin files or dropped webshells.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20361 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6172Icegram email subscribers \& newsletters sql injection vulnerabilityThe Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…EPSS 1.1%9.8CVE-2024-31352Icegram email subscribers \& newsletters missing authorization vulnerabilityMissing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.EPSS 0.39%9.8CVE-2024-4295Icegram email subscribers \& newsletters sql injection vulnerabilityThe Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and incl…EPSS 10%9.8CVE-2019-13569Icegram email subscribers \& newsletters sql injection vulnerabilityA SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of th…EPSS 3.7%8.8CVE-2022-3981Icegram email subscribers \& newsletters vulnerabilityThe Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a …EPSS 0.76%8.8CVE-2022-0439Icegram email subscribers \& newsletters sql injection vulnerabilityThe Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r…EPSS 4.2%7.5CVE-2018-6015Icegram email subscribers \& newsletters information exposure vulnerabilityAn issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=e…EPSS 3.2%6.5CVE-2024-12311Icegram email subscribers \& newsletters sql injection vulnerabilityThe Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, …EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2019-20361), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.