plugin

Email Artillery Vulnerabilities

11 known security issues reported for the Email Artillery WordPress plugin. Most recent disclosed Sep 13, 2021.

2 high 2 medium

Running Email Artillery on your site? Check whether your installed version is affected.

Scan your site free

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

[en] The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to th...

Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Sep 13, 2021

CVE-2021-24490 on NVD →

Email Artillery (MASS EMAIL) <= 4.1 - Arbitrary File Upload

high

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the pre...

CVSS:
7.2
Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

CVE-2021-24490 on NVD →

Email Artillery (MASS EMAIL) <= 4.1 - Authenticated SQL Injection

high

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various SQL Injection via the 'post_id' and 'email_id' parameters in versions up to, and including, 4.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
7.2
Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) <= 4.1 - Reflected Cross-Site Scripting

medium

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various Reflected Cross-Site Scripting via the 'cpage' and 'site_id' parameters in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) <= 4.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various Reflected Cross-Site Scripting via the 'cpage' and 'site_id' parameters in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various SQL Injection via the 'post_id' and 'email_id' parameters in versions up to, and including, 4.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The plugin does not sanitise, validate or escape its settings, and is lacking any CSRF check before saving them. As a result, an attacker could make a logged in admin change them and put malicious JavaScript code as well, leading to Stored Cross-Site Scripting issues.

Affected:
up to 4.1
Fix:
No patched version reported

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The plugin does not sanitise, validate or escape some user input before using it in SQL statements in the admin dashboard, leading to SQL Injections

Affected:
up to 4.1
Fix:
No patched version reported

Email Artillery (MASS EMAIL) [email-artillery] <= 4.1 (unfixed + closed)

unknown

The plugin does not sanitise, validate or escape some user input before outputting back in pages leading to Reflected Cross-Site Scripting issues which will be executed in the context of a logged in admin

Affected:
up to 4.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database