ALO EasyMail Newsletter [alo-easymail] < 2.6.01 (closed)
unknown
[en] The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
- Affected:
- up to 2.6.01
- Fixed in:
- 2.6.01
- Disclosed:
- Sep 25, 2019
CVE-2015-9409 on NVD →
ALO EasyMail Newsletter [alo-easymail] < 2.8.2 (closed)
unknown
Reflected Cross-Site Scripting (XSS) Vulnerability was found in WordPress ALO EasyMail Newsletter plugin in version 2.8.1. The file /alo-easymail-admin-subscribers.php outputs 'sortby' variable without escaping it.
Update the plugin.
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Apr 11, 2017
ALO EasyMail Newsletter <= 2.9.2 - Cross-Site Request Forgery
medium
The Alo Easymail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.2. This is due to missing or incorrect nonce validation on the import_step2 action. This makes it possible for unauthenticated attackers to import subscriber level users via a forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Aug 1, 2016
ALO EasyMail Newsletter [alo-easymail] < 2.9.3
unknown
The Alo Easymail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.2. This is due to missing or incorrect nonce validation on the import_step2 action. This makes it possible for unauthenticated attackers to import subscriber level users via a forged request granted t...
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Aug 1, 2016
ALO EasyMail Newsletter [alo-easymail] < 2.9.3 (closed)
unknown
ALO EasyMail NewsLetter Plugin prior to 2.9.3 is prone to a cross-site request forgery (CSRF). It allows remote attackers to add/import arbitrary subscribers.
Update ALO EasyMail NewsLetter plugin to 2.9.3 version.
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Jul 24, 2016
ALO EasyMail Newsletter <= 2.6.01 - Cross-Site Request Forgery
medium
The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.01. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to insert malicious code using a forged request granted they can trick a site...
- CVSS:
- 5.7
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Feb 16, 2016
ALO EasyMail Newsletter [alo-easymail] < 2.6.02 (closed)
unknown
ALO EasyMail Newsletter plugin is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.
Update the plugin.
- Affected:
- up to 2.6.02
- Fixed in:
- 2.6.02
- Disclosed:
- Feb 16, 2016
ALO EasyMail Newsletter [alo-easymail] < 2.6.01 (closed)
unknown
This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities.
Update the plugin.
- Affected:
- up to 2.6.01
- Fixed in:
- 2.6.01
- Disclosed:
- Feb 16, 2016
ALO EasyMail Newsletter [alo-easymail] < 2.7.0
unknown
The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.01. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to insert malicious code using a forged request granted they can trick a site...
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
- Disclosed:
- Feb 16, 2016
ALO EasyMail Newsletter <= 2.6.00 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
- CVSS:
- 8.8
- Affected:
- up to 2.6.01
- Fixed in:
- 2.6.01
- Disclosed:
- Sep 17, 2015
CVE-2015-9409 on NVD →
ALO EasyMail Newsletter [alo-easymail] < 2.4.8 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
- Disclosed:
- May 15, 2015
ALO EasyMail Newsletter [alo-easymail] < 2.9.3
unknown
The ALO EasyMail Newsletter WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
ALO EasyMail Newsletter [alo-easymail] < 2.7.0
unknown
The ALO EasyMail Newsletter WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.0
ALO EasyMail Newsletter [alo-easymail] < 2.4.8
unknown
The ALO EasyMail Newsletter WordPress plugin was affected by a Multiple Unspecified XSS security vulnerability.
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database