Extension WordPress
Vulnérabilités weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce
Cette page rassemble les failles publiées pour weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce
8 fiches
weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce <= 2.1.2 – Reflected Cross-Site Scripting
The weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes…
*-2.1.2
2.1.3
26/06/2026
weMail <= 2.0.7 – Missing Authorization to Unauthenticated Form Deletion
The weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()`…
*-2.0.7
2.0.8
20/02/2026
weMail <= 2.0.7 – Insufficient Authorization via x-wemail-user Header to Sensitive Information Disclosure
The weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST…
*-2.0.7
2.0.8
19/01/2026
weMail <= 1.14.13 – Unauthenticated Sensitive Information Exposure
The weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to Sensitive Information Exposure via the users() function in all versions up to, and including, 1.14.13. This makes…
*-1.14.13
1.14.14
07/05/2025
weMail <= 1.14.5 – Reflected Cross-Site Scripting
The weMail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.14.5
1.14.6
12/08/2024
weMail <= 1.14.2 – Missing Authorization to Notice Dismissal
The weMail plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the connect_notice() function in versions up to, and including, 1.14.2. This makes it possible for unauthenticated attackers to dismiss…
*-1.14.2
1.14.3
15/05/2024
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-1.14.1
1.14.2
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-1.14.1
1.14.2
14/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.