Show filters
126 Total Results
Displaying 51-60 of 126
Sort by:
Attacker Value
Unknown

CVE-2019-25141

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.
Attacker Value
Unknown

CVE-2023-2472

Disclosure Date: June 05, 2023 (last updated October 17, 2024)
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-1090

Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-29323

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
Attacker Value
Unknown

CVE-2023-0219

Disclosure Date: March 13, 2023 (last updated October 08, 2023)
The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.
Attacker Value
Unknown

CVE-2022-42699

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
Attacker Value
Unknown

CVE-2022-45833

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
Attacker Value
Unknown

CVE-2022-45829

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
Attacker Value
Unknown

CVE-2022-3334

Disclosure Date: October 31, 2022 (last updated December 22, 2024)
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Attacker Value
Unknown

CVE-2022-2352

Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.