Show filters
2,562 Total Results
Displaying 81-90 of 2,562
Sort by:
Attacker Value
Unknown
CVE-2024-54273
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker allows Object Injection.This issue affects Mail Picker: from n/a through 1.0.14.
0
Attacker Value
Unknown
CVE-2023-40203
Disclosure Date: December 13, 2024 (last updated February 12, 2025)
Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.
0
Attacker Value
Unknown
CVE-2023-32507
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Custom Emails: from n/a through 2.2.
0
Attacker Value
Unknown
CVE-2024-12441
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-11945
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-49156
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in GoDaddy GoDaddy Email Marketing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoDaddy Email Marketing: from n/a through 1.4.3.
0
Attacker Value
Unknown
CVE-2023-48332
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Tech Banker Mail Bank - #1 Mail SMTP Plugin for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mail Bank - #1 Mail SMTP Plugin for WordPress: from n/a through 4.0.14.
0
Attacker Value
Unknown
CVE-2023-47849
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in blossomthemes BlossomThemes Email Newsletter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.4.
0
Attacker Value
Unknown
CVE-2023-47756
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in David Vongries Welcome Email Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through 5.0.6.
0
Attacker Value
Unknown
CVE-2024-11436
Disclosure Date: December 07, 2024 (last updated December 21, 2024)
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0