plugin

Alo Easymail Vulnerabilities

14 known security issues reported for the Alo Easymail WordPress plugin. Most recent disclosed Sep 25, 2019.

1 high 2 medium

Running Alo Easymail on your site? Check whether your installed version is affected.

Scan your site free

ALO EasyMail Newsletter [alo-easymail] < 2.6.01 (closed)

unknown

[en] The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.

Affected:
up to 2.6.01
Fixed in:
2.6.01
Disclosed:
Sep 25, 2019

CVE-2015-9409 on NVD →

ALO EasyMail Newsletter [alo-easymail] < 2.8.2 (closed)

unknown

Reflected Cross-Site Scripting (XSS) Vulnerability was found in WordPress ALO EasyMail Newsletter plugin in version 2.8.1. The file /alo-easymail-admin-subscribers.php outputs 'sortby' variable without escaping it. Update the plugin.

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Apr 11, 2017

ALO EasyMail Newsletter <= 2.9.2 - Cross-Site Request Forgery

medium

The Alo Easymail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.2. This is due to missing or incorrect nonce validation on the import_step2 action. This makes it possible for unauthenticated attackers to import subscriber level users via a forged request granted t...

CVSS:
4.3
Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Aug 1, 2016

ALO EasyMail Newsletter [alo-easymail] < 2.9.3

unknown

The Alo Easymail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.2. This is due to missing or incorrect nonce validation on the import_step2 action. This makes it possible for unauthenticated attackers to import subscriber level users via a forged request granted t...

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Aug 1, 2016

ALO EasyMail Newsletter [alo-easymail] < 2.9.3 (closed)

unknown

ALO EasyMail NewsLetter Plugin prior to 2.9.3 is prone to a cross-site request forgery (CSRF). It allows remote attackers to add/import arbitrary subscribers. Update ALO EasyMail NewsLetter plugin to 2.9.3 version.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Jul 24, 2016

ALO EasyMail Newsletter <= 2.6.01 - Cross-Site Request Forgery

medium

The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.01. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to insert malicious code using a forged request granted they can trick a site...

CVSS:
5.7
Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Feb 16, 2016

ALO EasyMail Newsletter [alo-easymail] < 2.6.02 (closed)

unknown

ALO EasyMail Newsletter plugin is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session. Update the plugin.

Affected:
up to 2.6.02
Fixed in:
2.6.02
Disclosed:
Feb 16, 2016

ALO EasyMail Newsletter [alo-easymail] < 2.6.01 (closed)

unknown

This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities. Update the plugin.

Affected:
up to 2.6.01
Fixed in:
2.6.01
Disclosed:
Feb 16, 2016

ALO EasyMail Newsletter [alo-easymail] < 2.7.0

unknown

The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.01. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to insert malicious code using a forged request granted they can trick a site...

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Feb 16, 2016

ALO EasyMail Newsletter <= 2.6.00 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.

CVSS:
8.8
Affected:
up to 2.6.01
Fixed in:
2.6.01
Disclosed:
Sep 17, 2015

CVE-2015-9409 on NVD →

ALO EasyMail Newsletter [alo-easymail] < 2.4.8 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 2.4.8
Fixed in:
2.4.8
Disclosed:
May 15, 2015

ALO EasyMail Newsletter [alo-easymail] < 2.9.3

unknown

The ALO EasyMail Newsletter WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.9.3
Fixed in:
2.9.3

ALO EasyMail Newsletter [alo-easymail] < 2.7.0

unknown

The ALO EasyMail Newsletter WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.7.0
Fixed in:
2.7.0

ALO EasyMail Newsletter [alo-easymail] < 2.4.8

unknown

The ALO EasyMail Newsletter WordPress plugin was affected by a Multiple Unspecified XSS security vulnerability.

Affected:
up to 2.4.8
Fixed in:
2.4.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database