Extension WordPress
Vulnérabilités Newsletters, page 2
Cette page rassemble les failles publiées pour Newsletters, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Newsletters
30 fiches
Newsletters <= 4.9.5 – Reflected Cross-Site Scripting
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-4.9.5
4.9.6
06/06/2024
Newsletters <= 4.9.5 – Information Exposure via Log files
The Newsletters plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.5. This makes it possible for unauthenticated attackers to extract potentially sensitive information from log files.
*-4.9.5
4.9.6
22/04/2024
Newsletters <= 4.9.5 – Authenticated (Admin+) Arbitrary File Upload
The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with administrator-level access and above, to…
*-4.9.5
4.9.6
22/04/2024
Newsletter Lite <= 4.9.2 – Authenticated (Admin+) Command Injection
The Newsletters plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.9.2 via the emailarchive_olderthan parameter. This is due to insuffcient validation on user supplied input being passed to eval. This makes…
*-4.9.2
4.9.3
05/10/2023
Newsletters <= 4.8.8 – Cross-Site Request Forgery
The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.8. This is due to missing nonce validation on several cases in several functions like admin_groups() and admin_forms(). This makes it…
*-4.8.8
4.8.9
13/04/2023
Newsletters <= 4.6.18 – Directory Traversal
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
[*, 4.6.19)
4.6.19
01/07/2019
Newsletters <= 4.6.18 – Cross-Site Scripting via contentarea Parameter
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
[*, 4.6.19)
4.6.19
01/07/2019
Newsletters <= 4.6.8.5 – Object Injection
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
[*, 4.6.8.6)
4.6.8.6
12/03/2018
Newsletters <= 4.6.4.2 – Directory Traversal
The Newsletters plugin for WordPress is vulnerable to directory traversal due to insufficient validation on the data supplied via the 'file' parameter in versions up to, and including 4.6.4.2. This makes it possible for authenticated attackers to access…
*-4.6.4.2
4.6.4.3
29/05/2017
Newsletters <= 4.6.4.2 – Reflected Cross-Site Scripting
The Newsletters for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’, 'method', 'value', 'order', 'wpmlsearchterm', and 'wpmlmessage' parameters in versions up to, and including, 4.6.4.2 due to insufficient input sanitization and output escaping. This makes it…
*-4.6.5.2
4.6.5.3
29/05/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.