Cross-Site Request Forgery Vulnerability in Icegram Email Subscribers Plugin for WordPress
CVE-2020-5767
6.5MEDIUM
What is CVE-2020-5767?
The Icegram Email Subscribers & Newsletters Plugin for WordPress versions prior to 4.4.8 is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw allows a malicious actor to exploit the plugin by sending a crafted link to a legitimate user. When the user clicks on the link, the attacker can perform unintended actions on behalf of the user, such as sending forged emails. This can jeopardize user trust and lead to potential data breaches or phishing attacks.
Affected Version(s)
Icegram Email Subscribers & Newsletters Plugin for WordPress 4.4.8