Extension WordPress
Vulnérabilités Arigato Autoresponder and Newsletter
Cette page rassemble les failles publiées pour Arigato Autoresponder and Newsletter, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Arigato Autoresponder and Newsletter
18 fiches
Arigato Autoresponder and Newsletter <= 2.7.2.4 – Reflected Cross-Site Scripting
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.7.2.4
2.7.2.5
17/04/2025
Arigato Autoresponder and Newsletter <= 2.7.2.3 – Cross-Site Request Forgery
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2.3. This is due to missing or incorrect nonce validation on the contact_form() function. This makes it…
*-2.7.2.3
2.7.2.4
09/05/2024
Arigato Autoresponder and Newsletter <= 2.7.2.2 – Cross-Site Request Forgery
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.2.2. This is due to missing or incorrect nonce validation on the bft_log() function. This makes it possible…
*-2.7.2.2
2.7.2.3
09/11/2023
Arigato Autoresponder and Newsletter <= 2.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level…
*-2.7.1
2.7.1.1
06/02/2023
Arigato Autoresponder and Newsletter <= 2.7.1 – Unauthenticated Stored Cross-Site Scripting
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.7.1
2.7.1.1
06/02/2023
Arigato Autoresponder and Newsletter <= 2.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor…
*-2.7.1
2.7.1.1
02/02/2023
Arigato Autoresponder and Newsletter <= 2.1.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$user->email’ parameter in versions up to, and including, 2.1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.1.7.1
2.1.7.2
31/01/2023
Arigato Autoresponder and Newsletter <= 2.7 – Arbitrary File Upload
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.This plugin does not appear to be patched based on our review.
*
Non indiqué
17/10/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – SQL Injection
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.
*-2.5.1.8
2.5.1.9
18/09/2018
Arigato Autoresponder and Newsletter <= 2.5.1.8 – Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.
*-2.5.1.8
2.5.1.9
18/09/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.