Extension WordPress
Vulnérabilités WP-EMail
Cette page rassemble les failles publiées pour WP-EMail, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-EMail
5 fiches
WP-EMail <= 2.69.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP-EMail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.69.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
[*, 2.69.1)
2.69.1
24/07/2023
WP-EMail <= 2.68.2 – Cross-Site Request Forgery to Log Deletion
The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack
[*, 2.69.0)
2.69.0
30/05/2022
WP-EMail <= 2.68.2 – Spam Protection Bypass
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
[*, 2.69.0)
2.69.0
30/05/2022
WP-EMail <= 2.67.2 – Unauthenticated Cross-Site Scripting
The WP-EMail plugin for WordPress is vulnerable to Cross-Site Scripting via several form fields in versions up to, and including, 2.67.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.67.2
2.67.3
07/07/2016
WP-EMail < 2.67.2 – SQL Injection
The WP-EMail Plugin for WordPress is vulnerable to SQL Injection via the ‘last_emailed’ parameter in versions before 2.67.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
[*, 2.67.2)
2.67.2
14/05/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.