Email Before Download <= 6.9.7 - Cross-Site Request Forgery
medium
The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation on the purge_data function. This makes it possible for unauthenticated attackers to purge data via a forged request granted they ca...
- CVSS:
- 5.3
- Affected:
- up to 6.9.7
- Fixed in:
- 6.9.8
- Disclosed:
- Jan 30, 2024
CVE-2024-23519 on NVD →
Email Before Download <= 6.7 - Admin+ SQL Injection
high
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
- CVSS:
- 7.2
- Affected:
- up to 6.7
- Fixed in:
- 6.8
- Disclosed:
- Nov 1, 2021
CVE-2021-24748 on NVD →
Email Before Download <= 3.6 - SQL Injection
critical
The Email Before Download plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries int...
- CVSS:
- 9.8
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jun 21, 2017
Email Before Download <= 3.6 - SMTP Header Injection
medium
The Email Before Download plugin for WordPress is vulnerable to SMTP Header Injection in versions up to, and including, 3.6 via the 'email_from' POST parameter, where the 'emailfrom' variable is concatenated in the SMTP 'From:' header and then directly passed to wp_mail. This makes it possible for unauthenticated attac...
- CVSS:
- 5.8
- Affected:
- up to 3.6
- Fixed in:
- 4.0
- Disclosed:
- Jun 21, 2017
Email Before Download <= 3.4 - SQL Injection
critical
The Email Before Download plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4 due to insufficient escaping on several user-supplied parameters and lack of sufficient preparation on existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL...
- CVSS:
- 9.8
- Affected:
- up to 3.4
- Fixed in:
- 3.4.1
- Disclosed:
- Jul 28, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database