Extension WordPress

Vulnérabilités Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress, page 2

Cette page rassemble les failles publiées pour Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

43Vulnérabilités
6Critiques
43Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

43 fiches

CVE-2024-4010 Élevée · 8,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers by Icegram Express <= 5.7.19 – Missing Authorization in handle_ajax_request

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to,…

Versions affectées

*-5.7.19

Correctif

5.7.20

Publication

14/05/2024

CVE-2024-2876 Critique · 9,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 – Unauthenticated SQL Injection

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including,…

Versions affectées

*-5.7.14

Correctif

5.7.15

Publication

15/04/2024

CVE-2024-31352 Moyenne · 5,3
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 5.7.13 – Missing Authorization

The Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 5.7.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Versions affectées

*-5.7.13

Correctif

5.7.14

Publication

05/04/2024

CVE-2024-2656 Moyenne · 4,4
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Express <= 5.7.14 – Authenticated (Administrator+) Cross-Site Scripting via CSV import

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to…

Versions affectées

*-5.7.15

Correctif

5.7.16

Publication

05/04/2024

CVE-2024-22300 Moyenne · 6,1
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 5.7.11 – Reflected Cross-Site Scripting via campaign_id

The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘campaign_id' parameter in versions up to, and including, 5.7.11 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.7.11

Correctif

5.7.12

Publication

26/03/2024

CVE-2023-5414 Critique · 9,1
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Express <= 5.6.23 – Authenticated (Administrator+) Directory Traversal to Arbitrary File Read

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can…

Versions affectées

*-5.6.23

Correctif

5.6.24

Publication

11/10/2023

CVE-2022-45810 Moyenne · 6,5
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Express <= 5.5.2 – Unauthenticated CSV Injection

The Icegram Express plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.5.2. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these…

Versions affectées

*-5.5.2

Correctif

5.5.3

Publication

06/02/2023

CVE-2022-3981 Élevée · 8,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Express <= 5.4.19 – Authenticated (Subscriber+) SQL Injection

The Icegram Express plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.19 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

Versions affectées

*-5.4.19

Correctif

5.5.0

Publication

21/11/2022

CVE-2022-0439 Élevée · 8,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 5.3.1 – Authenticated (or Cross-Site Request Forgery) Blind SQL Injection

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber.…

Versions affectées

[*, 5.3.2)

Correctif

5.3.2

Publication

11/02/2022

CVE-2020-5780 Moyenne · 5,3
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 4.5.5 – Unauthenticated Email Forgery

Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.

Versions affectées

[*, 4.5.6)

Correctif

4.5.6

Publication

09/09/2020

CVE-2020-5768 Moyenne · 4,9
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Email Subscribers & Newsletters <= 4.5.0 – Authenticated SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.

Versions affectées

[*, 4.5.1)

Correctif

4.5.1

Publication

16/07/2020

CVE-2020-5767 Élevée · 8,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Icegram Email Subscribers & Newsletters Plugin for WordPress <= 4.5.0 – Cross-Site Request Forgery

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.5.0 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

Versions affectées

[*, 4.5.1)

Correctif

4.5.1

Publication

13/07/2020

CVE-2019-19982 Moyenne · 6,5
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 4.2.2 – Unauthenticated Option Creation

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.

Versions affectées

*-4.2.2

Correctif

4.2.3

Publication

13/11/2019

CVE-2019-19980 Moyenne · 4,3
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 4.2.2 – Missing Authorization to Test Email

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because…

Versions affectées

*-4.2.2

Correctif

4.2.3

Publication

13/11/2019

CVE-2019-20361 Élevée · 8,3
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters < 4.3.1 – Unauthenticated Blind SQL Injection

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

Versions affectées

*-4.3.0

Correctif

4.3.1

Publication

13/11/2019

CVE-2019-13569 Critique · 9,8
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 4.1.7 – SQL Injection

A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

Versions affectées

*-4.1.7

Correctif

4.1.8

Publication

22/07/2019

CVE-2019-14364 Moyenne · 6,1
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress

Email Subscribers & Newsletters <= 4.1.6 – Cross-Site Scripting

An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.

Versions affectées

*-4.1.6

Correctif

4.1.7

Publication

12/07/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités