The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
- https://wpvulndb.com/vulnerabilities/9946
- https://github.com/20142995/nuclei-templates