Show filters
46 Total Results
Displaying 31-40 of 46
Sort by:
Attacker Value
Unknown
CVE-2021-24941
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-36832
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
0
Attacker Value
Unknown
CVE-2020-5780
Disclosure Date: September 10, 2020 (last updated February 22, 2025)
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
0
Attacker Value
Unknown
CVE-2020-5767
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
0
Attacker Value
Unknown
CVE-2020-5768
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
0
Attacker Value
Unknown
CVE-2019-19981
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
0
Attacker Value
Unknown
CVE-2019-19982
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
0
Attacker Value
Unknown
CVE-2019-19984
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
0
Attacker Value
Unknown
CVE-2019-19980
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.
0
Attacker Value
Unknown
CVE-2016-10963
Disclosure Date: September 16, 2019 (last updated January 11, 2024)
The icegram plugin before 1.9.19 for WordPress has XSS.
0