plugin

Bft Autoresponder Vulnerabilities

37 known security issues reported for the Bft Autoresponder WordPress plugin. Most recent disclosed Apr 17, 2025.

1 critical 2 high 15 medium

Running Bft Autoresponder on your site? Check whether your installed version is affected.

Scan your site free

Arigato Autoresponder and Newsletter <= 2.7.2.4 - Reflected Cross-Site Scripting

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 2.7.2.4
Fixed in:
2.7.2.5
Disclosed:
Apr 17, 2025

CVE-2025-39594 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.2.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4.

Affected:
up to 2.7.2.5
Fixed in:
2.7.2.5
Disclosed:
Apr 17, 2025

CVE-2025-39594 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.2.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3.

Affected:
up to 2.7.2.4
Fixed in:
2.7.2.4
Disclosed:
May 10, 2024

CVE-2024-34823 on NVD →

Arigato Autoresponder and Newsletter <= 2.7.2.3 - Cross-Site Request Forgery

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2.3. This is due to missing or incorrect nonce validation on the contact_form() function. This makes it possible for unauthenticated attackers to modify contact form detail...

CVSS:
4.3
Affected:
up to 2.7.2.3
Fixed in:
2.7.2.4
Disclosed:
May 9, 2024

CVE-2024-34823 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.2.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions.

Affected:
up to 2.7.2.3
Fixed in:
2.7.2.3
Disclosed:
Nov 16, 2023

CVE-2023-47686 on NVD →

Arigato Autoresponder and Newsletter <= 2.7.2.2 - Cross-Site Request Forgery

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.2.2. This is due to missing or incorrect nonce validation on the bft_log() function. This makes it possible for unauthenticated attackers to trigger the view of all raw email l...

CVSS:
4.3
Affected:
up to 2.7.2.2
Fixed in:
2.7.2.3
Disclosed:
Nov 9, 2023

CVE-2023-47686 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.1.1

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions.

Affected:
up to 2.7.1.1
Fixed in:
2.7.1.1
Disclosed:
Apr 7, 2023

CVE-2023-25031 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.1.2

unknown

[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

Affected:
up to 2.7.1.2
Fixed in:
2.7.1.2
Disclosed:
Apr 7, 2023

CVE-2023-25020 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.1.2

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

Affected:
up to 2.7.1.2
Fixed in:
2.7.1.2
Disclosed:
Apr 7, 2023

CVE-2023-25061 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.7.1.2

unknown

[en] The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 2.7.1.2
Fixed in:
2.7.1.2
Disclosed:
Feb 27, 2023

CVE-2023-0543 on NVD →

Arigato Autoresponder and Newsletter <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

high

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w...

CVSS:
7.2
Affected:
up to 2.7.1
Fixed in:
2.7.1.1
Disclosed:
Feb 6, 2023

CVE-2023-25020 on NVD →

Arigato Autoresponder and Newsletter <= 2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level permissions to inject arbitrary web s...

CVSS:
5.5
Affected:
up to 2.7.1
Fixed in:
2.7.1.1
Disclosed:
Feb 6, 2023

CVE-2023-25031 on NVD →

Arigato Autoresponder and Newsletter <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level access to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.7.1
Fixed in:
2.7.1.1
Disclosed:
Feb 2, 2023

CVE-2023-25061 on NVD →

Arigato Autoresponder and Newsletter <= 2.1.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$user->email’ parameter in versions up to, and including, 2.1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin level access to...

CVSS:
4.4
Affected:
up to 2.1.7.1
Fixed in:
2.1.7.2
Disclosed:
Jan 31, 2023

CVE-2023-0543 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.2

unknown

Authenticated reflected Cross-Site Scripting (XSS) vulnerability found by Larry W. Cashdollar in WordPress Arigato Autoresponder and Newsletter plugin (versions <= 2.5.1.8).

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Dec 4, 2018

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002000 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002009 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002008 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.2

unknown

[en] These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Dec 3, 2018

CVE-2018-1002006 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002005 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002004 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002001 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002003 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002002 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.5.1.9

unknown

[en] There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.

Affected:
up to 2.5.1.9
Fixed in:
2.5.1.9
Disclosed:
Dec 3, 2018

CVE-2018-1002007 on NVD →

Arigato Autoresponder and Newsletter [bft-autoresponder] < 2.6

unknown

[en] The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Oct 18, 2018

CVE-2018-18461 on NVD →

Arigato Autoresponder and Newsletter <= 2.7 - Arbitrary File Upload

critical

The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.This plugin does not appear to be patched based on our review.

CVSS:
9.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Oct 17, 2018

CVE-2018-18461 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - SQL Injection

high

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

CVSS:
7.2
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002000 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002001 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002008 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002009 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002002 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002003 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002007 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting

medium

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

CVSS:
6.1
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002004 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Cross-Site Scripting

medium

These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.

CVSS:
4.8
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002005 on NVD →

Arigato Autoresponder and Newsletter <= 2.5.1.8 - Cross-Site Scripting

medium

These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes

CVSS:
4.8
Affected:
up to 2.5.1.8
Fixed in:
2.5.1.9
Disclosed:
Sep 18, 2018

CVE-2018-1002006 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database