Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-10103

Disclosure Date: November 19, 2024 (last updated November 19, 2024)
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
0
Attacker Value
Unknown

CVE-2024-9938

Disclosure Date: November 16, 2024 (last updated November 16, 2024)
The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.3.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2019-11843

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
Attacker Value
Unknown

CVE-2018-20853

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
Attacker Value
Unknown

CVE-2014-3907

Disclosure Date: August 26, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2014-4725

Disclosure Date: July 27, 2014 (last updated October 05, 2023)
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
0
Attacker Value
Unknown

CVE-2014-4726

Disclosure Date: July 27, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
0