Extension WordPress
Vulnérabilités Kadence WooCommerce Email Designer
Cette page rassemble les failles publiées pour Kadence WooCommerce Email Designer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Kadence WooCommerce Email Designer
5 fiches
Kadence WooCommerce Email Designer <= 1.5.17 – Unauthenticated Stored Cross-Site Scripting
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.5.17
1.5.18
01/12/2025
Kadence WooCommerce Email Designer <= 1.5.16 – Authenticated (Shop Manager+) Arbitrary Options Update
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to insufficient input validation on the import_woomail() function in all versions up to, and including, 1.5.16.…
*-1.5.16
1.5.17
14/08/2025
Kadence WooCommerce Email Designer <= 1.5.14 – Authenticated (Admin+) Arbitrary File Upload
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.14. This makes it possible for authenticated attackers, with Administrator-level access…
*-1.5.14
1.5.15
16/04/2025
Kadence WooCommerce Email Designer <= 1.5.11 – Cross-Site Request Forgery
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.11. This is due to missing or incorrect nonce validation on the ajax_reset() and ajax_send_email() functions. This…
*-1.5.11
1.5.12
02/11/2023
Kadence WooCommerce Email Designer <= 1.5.6 – PHP Object Injection
The Kadence WooCommerce Email Designer for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.6 via deserialization of untrusted input via the 'raw' parameter in the import_woomail function. This allows administrator-level attackers or…
*-1.5.6
1.5.7
30/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.