Extension WordPress
Vulnérabilités Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress, page 2
Cette page rassemble les failles publiées pour Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
43 fiches
Email Subscribers by Icegram Express <= 5.7.19 – Missing Authorization in handle_ajax_request
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to,…
*-5.7.19
5.7.20
14/05/2024
Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 – Unauthenticated SQL Injection
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including,…
*-5.7.14
5.7.15
15/04/2024
Email Subscribers & Newsletters <= 5.7.13 – Missing Authorization
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 5.7.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-5.7.13
5.7.14
05/04/2024
Icegram Express <= 5.7.14 – Authenticated (Administrator+) Cross-Site Scripting via CSV import
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to…
*-5.7.15
5.7.16
05/04/2024
Email Subscribers & Newsletters <= 5.7.11 – Reflected Cross-Site Scripting via campaign_id
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘campaign_id' parameter in versions up to, and including, 5.7.11 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.7.11
5.7.12
26/03/2024
Icegram Express <= 5.6.23 – Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can…
*-5.6.23
5.6.24
11/10/2023
Icegram Express <= 5.5.2 – Unauthenticated CSV Injection
The Icegram Express plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.5.2. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these…
*-5.5.2
5.5.3
06/02/2023
Icegram Express <= 5.4.19 – Authenticated (Subscriber+) SQL Injection
The Icegram Express plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.19 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-5.4.19
5.5.0
21/11/2022
Email Subscribers & Newsletters <= 5.3.1 – Authenticated (or Cross-Site Request Forgery) Blind SQL Injection
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber.…
[*, 5.3.2)
5.3.2
11/02/2022
Email Subscribers & Newsletters <= 4.5.5 – Unauthenticated Email Forgery
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
[*, 4.5.6)
4.5.6
09/09/2020
Icegram Email Subscribers & Newsletters <= 4.5.0 – Authenticated SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
[*, 4.5.1)
4.5.1
16/07/2020
Icegram Email Subscribers & Newsletters Plugin for WordPress <= 4.5.0 – Cross-Site Request Forgery
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.5.0 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
[*, 4.5.1)
4.5.1
13/07/2020
Email Subscribers & Newsletters <= 4.2.2 – Unauthenticated Option Creation
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
*-4.2.2
4.2.3
13/11/2019
Email Subscribers & Newsletters <= 4.2.2 – Cross-Site Request Forgery on Settings
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
*-4.2.2
4.2.3
13/11/2019
Email Subscribers & Newsletters <= 4.2.2 – Unauthenticated File Download w/ Information Disclosure
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
*-4.2.2
4.2.3
13/11/2019
Email Subscribers & Newsletters <= 4.2.2 – Missing Authorization to Test Email
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because…
*-4.2.2
4.2.3
13/11/2019
Email Subscribers & Newsletters <= 4.2.2 – Missing Authorization
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
*-4.2.2
4.2.3
13/11/2019
Email Subscribers & Newsletters < 4.3.1 – Unauthenticated Blind SQL Injection
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
*-4.3.0
4.3.1
13/11/2019
Email Subscribers & Newsletters <= 4.1.7 – SQL Injection
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
*-4.1.7
4.1.8
22/07/2019
Email Subscribers & Newsletters <= 4.1.6 – Cross-Site Scripting
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
*-4.1.6
4.1.7
12/07/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.