WordPress Email Subscribers & Newsletters plugin before 4.2.3 is susceptible to arbitrary file retrieval via a flaw that allows unauthenticated file download and user information disclosure. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
id: CVE-2019-19985
info:
name: WordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File
...