Extension WordPress
Vulnérabilités Email Marketing Plugin – WP Email Capture
Cette page rassemble les failles publiées pour Email Marketing Plugin – WP Email Capture, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Email Marketing Plugin – WP Email Capture
6 fiches
Email Capture <= 3.12.5 – Cross-Site Request Forgery
The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.5. This is due to missing or incorrect nonce validation on a function. This…
*-3.12.5
3.12.6
31/12/2025
Email Capture <= 3.12.4 – Missing Authorization
The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.12.4. This makes it possible for…
*-3.12.4
3.12.5
08/12/2025
WordPress Email Marketing Plugin – WP Email Capture <= 3.10 – Information Exposure via wp_email_capture_options_process
The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.10 via the wp_email_capture_options_process function hooked via admin_init. This makes it possible for unauthenticated…
*-3.10
3.11
15/03/2023
WordPress Email Marketing Plugin – WP Email Capture <= 3.10 – Missing Authorization to Email Capture List Download
The WP Email Capture plugin for WordPress is vulnerable to unauthorized Email Capture list download due to a missing capability check on the wp_email_capture_options_process function in versions up to, and including, 3.10. This makes it possible for unauthenticated…
*-3.10
3.11
14/03/2023
WordPress Email Marketing Plugin – WP Email Capture <= 3.9.3 – Cross Site Request Forgery
The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.3. This is due to missing nonce validation in the wp_email_capture_options_process() function. This makes…
*-3.9.3
3.10
15/02/2023
WP Email Capture <= 3.9.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Email Capture plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.9.3
3.10
30/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.