plugin

Email Before Download Vulnerabilities

5 known security issues reported for the Email Before Download WordPress plugin. Most recent disclosed Jan 30, 2024.

2 critical 1 high 2 medium

Running Email Before Download on your site? Check whether your installed version is affected.

Scan your site free

Email Before Download <= 6.9.7 - Cross-Site Request Forgery

medium

The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation on the purge_data function. This makes it possible for unauthenticated attackers to purge data via a forged request granted they ca...

CVSS:
5.3
Affected:
up to 6.9.7
Fixed in:
6.9.8
Disclosed:
Jan 30, 2024

CVE-2024-23519 on NVD →

Email Before Download <= 6.7 - Admin+ SQL Injection

high

The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

CVSS:
7.2
Affected:
up to 6.7
Fixed in:
6.8
Disclosed:
Nov 1, 2021

CVE-2021-24748 on NVD →

Email Before Download <= 3.6 - SQL Injection

critical

The Email Before Download plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries int...

CVSS:
9.8
Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Jun 21, 2017

Email Before Download <= 3.6 - SMTP Header Injection

medium

The Email Before Download plugin for WordPress is vulnerable to SMTP Header Injection in versions up to, and including, 3.6 via the 'email_from' POST parameter, where the 'emailfrom' variable is concatenated in the SMTP 'From:' header and then directly passed to wp_mail. This makes it possible for unauthenticated attac...

CVSS:
5.8
Affected:
up to 3.6
Fixed in:
4.0
Disclosed:
Jun 21, 2017

Email Before Download <= 3.4 - SQL Injection

critical

The Email Before Download plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4 due to insufficient escaping on several user-supplied parameters and lack of sufficient preparation on existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL...

CVSS:
9.8
Affected:
up to 3.4
Fixed in:
3.4.1
Disclosed:
Jul 28, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database