plugin

Blossomthemes Email Newsletter Vulnerabilities

4 known security issues reported for the Blossomthemes Email Newsletter WordPress plugin. Most recent disclosed Dec 9, 2024.

2 medium

Running Blossomthemes Email Newsletter on your site? Check whether your installed version is affected.

Scan your site free

BlossomThemes Email Newsletter [blossomthemes-email-newsletter] < 2.2.5

unknown

[en] Missing Authorization vulnerability in blossomthemes BlossomThemes Email Newsletter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.4.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Dec 9, 2024

CVE-2023-47849 on NVD →

BlossomThemes Email Newsletter [blossomthemes-email-newsletter] < 2.2.7

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Jun 26, 2024

CVE-2024-37098 on NVD →

BlossomThemes Email Newsletter <= 2.2.6 - Authenticated (Admin+) Server-Side Request Forgery

medium

The BlossomThemes Email Newsletter plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web applicatio...

CVSS:
5.5
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jun 20, 2024

CVE-2024-37098 on NVD →

BlossomThemes Email Newsletter <= 2.2.4 - Missing Authorization

medium

The BlossomThemes Email Newsletter plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the bten_get_mailing_list function in versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to obtain a mailing list.

CVSS:
5.3
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Nov 20, 2023

CVE-2023-47849 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database