Extension WordPress

Vulnérabilités Email Marketing for WooCommerce by Omnisend

Cette page rassemble les failles publiées pour Email Marketing for WooCommerce by Omnisend, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Email Marketing for WooCommerce by Omnisend

4 fiches

CVE-2026-57632 Moyenne · 4,3
Email Marketing for WooCommerce by Omnisend

Email Marketing for WooCommerce by Omnisend <= 1.19.0 – Missing Authorization

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.0. This makes it possible for authenticated attackers,…

Versions affectées

*-1.19.0

Correctif

1.19.1

Publication

26/06/2026

CVE-2026-42668 Élevée · 7,5
Email Marketing for WooCommerce by Omnisend

Omnisend for WooCommerce <= 1.18.0 – Unauthenticated Omnisend Account Takeover via Predictable Connect Token

The Omnisend for WooCommerce plugin for WordPress is vulnerable to an unauthenticated account takeover via insufficiently random values in versions up to, and including, 1.18.0. This is due to the generate_install_url() function deriving the OAuth connect token solely…

Versions affectées

*-1.18.0

Correctif

1.18.1

Publication

13/05/2026

CVE-2024-32101 Moyenne · 4,3
Email Marketing for WooCommerce by Omnisend

Email Marketing for WooCommerce by Omnisend <= 1.14.3 – Cross-Site Request Forgery

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.14.3. This is due to missing or incorrect nonce validation on the 'log_options' action. This makes…

Versions affectées

*-1.14.3

Correctif

1.14.4

Publication

11/04/2024

CVE-2023-47244 Moyenne · 5,3
Email Marketing for WooCommerce by Omnisend

Email Marketing for WooCommerce by Omnisend <= 1.13.8 – Sensitive Information Exposure

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the status REST API endpoint. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.13.8

Correctif

1.13.9

Publication

07/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités