Extension WordPress
Vulnérabilités Newsletter Manager
Cette page rassemble les failles publiées pour Newsletter Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Newsletter Manager
5 fiches
Newsletter Manager <= 1.5.1 – Insecure Deserialization
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it…
*-1.5.1
Non indiqué
29/12/2020
Newsletter Manager <= 1.4 – Open Redirect
The Newsletter Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.4. This is due to improper validation of the 'appurl' parameter. This makes it possible for unauthenticated attackers to redirect traffic…
*-1.4
1.5
18/05/2019
Newsletter Manager < 1.4 – Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin before 1.4 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change an email address or (2) conduct script insertion attacks.
[*, 1.4)
1.4
16/01/2014
Newsletter Manager < 1.0.2 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) xyz_em_campName to admin/create_campaign.php or (2) admin/edit_campaign.php, (3) xyz_em_email parameter to admin/edit_email.php,…
[*, 1.0.2)
1.0.2
15/05/2012
Newsletter Manager < 1.0.2 – Cross-Site Scripting via test_mail.php
Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin before 1.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.
[*, 1.0.2)
1.0.2
15/05/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.