plugin

Easy Newsletter Signups Vulnerabilities

10 known security issues reported for the Easy Newsletter Signups WordPress plugin. Most recent disclosed Dec 13, 2024.

1 high 2 medium

Running Easy Newsletter Signups on your site? Check whether your installed version is affected.

Scan your site free

Easy Newsletter Signups [easy-newsletter-signups] <= 1.0.4 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in AlphaBPO Easy Newsletter Signups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Newsletter Signups: from n/a through 1.0.4.

Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Dec 13, 2024

CVE-2023-41664 on NVD →

Easy Newsletter Signups [easy-newsletter-signups] < 1.0.4 (closed)

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Easy Newsletter Signups [easy-newsletter-signups] <= 1.0.4 (closed)

unknown

[en] The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Dec 4, 2023

CVE-2023-5108 on NVD →

Easy Newsletter Signups <= 1.0.4 - Authenticated (Admin+) SQL Injection

high

The Easy Newsletter Signups plugin for WordPress is vulnerable to SQL Injection via the 'nsl_id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...

CVSS:
7.2
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Nov 13, 2023

CVE-2023-5108 on NVD →

Easy Newsletter Signups <= 1.0.4 - Missing Authorization

medium

The Easy Newsletter Signups plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to a missing capability check on the wpesn_ltable_process_bulk_action() function hooked via admin_init in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to d...

CVSS:
6.5
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Sep 1, 2023

CVE-2023-41664 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Easy Newsletter Signups [easy-newsletter-signups] < 1.0.4 (closed)

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Mar 4, 2022

Easy Newsletter Signups [easy-newsletter-signups] < 1.0.4 (closed)

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Easy Newsletter Signups plugin (versions <= 1.0.3).

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Feb 28, 2022

Easy Newsletter Signups [easy-newsletter-signups] < 1.0.4 (closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Easy Newsletter Signups plugin (versions <= 1.0.3).

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Feb 28, 2022

Easy Newsletter Signups [easy-newsletter-signups] <= 1.0.4 (unfixed + closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.0.4
Fix:
No patched version reported

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database