Extension WordPress
Vulnérabilités EmailKit – Email Customizer for WooCommerce & WP
Cette page rassemble les failles publiées pour EmailKit – Email Customizer for WooCommerce & WP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de EmailKit – Email Customizer for WooCommerce & WP
5 fiches
EmailKit <= 1.6.5 – Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath()…
*-1.6.5
1.6.6
04/05/2026
EmailKit <= 1.6.3 – Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the…
*-1.6.3
1.6.4
20/03/2026
EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes…
*-1.6.2
1.6.3
17/02/2026
EmailKit <= 1.6.1 – Authenticated (Author+) Arbitrary File Read via Path Traversal
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input…
*-1.6.1
1.6.2
06/01/2026
EmailKit <= 1.6.0 – Missing Authorization to Authenticated (Author+) Arbitrary Content Deletion
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.0. This makes it possible…
*-1.6.0
1.6.1
26/09/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.