Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
medium
The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes...
- CVSS:
- 4.3
- Affected:
- up to 5.9.27
- Fixed in:
- 5.9.28
- Disclosed:
- Jul 1, 2026
CVE-2026-11592 on NVD →
Email Subscribers & Newsletters - Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter vulnerability
high
Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter vulnerability
- CVSS:
- 7.6
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.17
- Disclosed:
- Mar 3, 2026
Email Subscribers & Newsletters <= 5.9.16 - Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter
medium
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- CVSS:
- 6.5
- Affected:
- up to 5.9.16
- Fixed in:
- 5.9.17
- Disclosed:
- Mar 3, 2026
CVE-2026-1651 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.9.11
unknown
[en] The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `run_action_scheduler_task` func...
- Affected:
- up to 5.9.11
- Fixed in:
- 5.9.11
- Disclosed:
- Dec 12, 2025
CVE-2025-12348 on NVD →
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task Execution
medium
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `run_action_scheduler_task` function....
- CVSS:
- 5.3
- Affected:
- up to 5.9.10
- Fixed in:
- 5.9.11
- Disclosed:
- Dec 11, 2025
CVE-2025-12348 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] <= 5.9.10 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.
- Affected:
- up to 5.9.10
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66055 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.9.11
unknown
[en] The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `trigger_mailing_queue_sending` function...
- Affected:
- up to 5.9.11
- Fixed in:
- 5.9.11
- Disclosed:
- Nov 19, 2025
CVE-2025-12349 on NVD →
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger
medium
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `trigger_mailing_queue_sending` function. Thi...
- CVSS:
- 5.3
- Affected:
- up to 5.9.10
- Fixed in:
- 5.9.11
- Disclosed:
- Nov 18, 2025
CVE-2025-12349 on NVD →
Email Subscribers & Newsletters <= 5.9.10 - Authenticated (Administrator+) PHP Object Injection
medium
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is pre...
- CVSS:
- 6.6
- Affected:
- up to 5.9.10
- Fixed in:
- 5.9.11
- Disclosed:
- Nov 8, 2025
CVE-2025-66055 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.52
unknown
[en] The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi...
- Affected:
- up to 5.7.52
- Fixed in:
- 5.7.52
- Disclosed:
- Apr 17, 2025
CVE-2024-11924 on NVD →
Email Subscribers & Newsletters <= 5.7.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Icegram Express formerly known as Email Subscribers – The Ultimate Email Marketing & Automation Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.7.49 due to insufficient input sanitization and output escaping. This make...
- CVSS:
- 4.4
- Affected:
- up to 5.7.49
- Fixed in:
- 5.7.50
- Disclosed:
- Apr 3, 2025
CVE-2025-0671 on NVD →
Email Subscribers & Newsletters <= 5.7.51 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Icegram Express formerly known as Email Subscribers – The Ultimate Email Marketing & Automation Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.7.51 due to insufficient input sanitization and output escaping. This make...
- CVSS:
- 4.4
- Affected:
- up to 5.7.51
- Fixed in:
- 5.7.52
- Disclosed:
- Mar 27, 2025
CVE-2024-11924 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.45
unknown
[en] The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.7.45
- Fixed in:
- 5.7.45
- Disclosed:
- Jan 13, 2025
CVE-2024-12566 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.45
unknown
[en] The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite s...
- Affected:
- up to 5.7.45
- Fixed in:
- 5.7.45
- Disclosed:
- Jan 13, 2025
CVE-2024-12568 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.45
unknown
[en] The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...
- Affected:
- up to 5.7.45
- Fixed in:
- 5.7.45
- Disclosed:
- Jan 13, 2025
CVE-2024-11636 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.45
unknown
[en] The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup...
- Affected:
- up to 5.7.45
- Fixed in:
- 5.7.45
- Disclosed:
- Jan 13, 2025
CVE-2024-12567 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.44
unknown
[en] The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected:
- up to 5.7.44
- Fixed in:
- 5.7.44
- Disclosed:
- Jan 6, 2025
CVE-2024-12311 on NVD →
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce <= 5.7.44 - Authenticated (Admin+) Stored Cross-Site Scripting via Workflow Settings
medium
The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Workflow Settings in all versions up to, and including, 5.7.44 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 4.4
- Affected:
- up to 5.7.44
- Fixed in:
- 5.7.45
- Disclosed:
- Dec 23, 2024
CVE-2024-12568 on NVD →
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce <= 5.7.44 - Authenticated (Admin+) Stored Cross-Site Scripting via Text Block
medium
The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Block options in all versions up to, and including, 5.7.44 due to insufficient input sanitization and output escaping. This makes it poss...
- CVSS:
- 4.4
- Affected:
- up to 5.7.44
- Fixed in:
- 5.7.45
- Disclosed:
- Dec 23, 2024
CVE-2024-11636 on NVD →
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce <= 5.7.44 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.7.44 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 4.4
- Affected:
- up to 5.7.44
- Fixed in:
- 5.7.45
- Disclosed:
- Dec 23, 2024
CVE-2024-12566 on NVD →
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce <= 5.7.44 - Authenticated (Admin+) Stored Cross-Site Scripting via Form Settings
medium
The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.7.44 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 4.4
- Affected:
- up to 5.7.44
- Fixed in:
- 5.7.45
- Disclosed:
- Dec 23, 2024
CVE-2024-12567 on NVD →
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce <= 5.7.43 - Authenticated (Admin+) SQL Injection
medium
The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'data[datalorder_by_column]' parameter in all versions up to, and including, 5.7.43 due to insufficient escaping on the user supplied parameter and lack...
- CVSS:
- 4.9
- Affected:
- up to 5.7.43
- Fixed in:
- 5.7.44
- Disclosed:
- Dec 16, 2024
CVE-2024-12311 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.35
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly va...
- Affected:
- up to 5.7.35
- Fixed in:
- 5.7.35
- Disclosed:
- Oct 2, 2024
CVE-2024-8254 on NVD →
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly validat...
- CVSS:
- 5.4
- Affected:
- up to 5.7.34
- Fixed in:
- 5.7.35
- Disclosed:
- Oct 1, 2024
CVE-2024-8254 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.35
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This make...
- Affected:
- up to 5.7.35
- Fixed in:
- 5.7.35
- Disclosed:
- Sep 26, 2024
CVE-2024-8771 on NVD →
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
medium
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 5.7.34
- Fixed in:
- 5.7.35
- Disclosed:
- Sep 25, 2024
CVE-2024-8771 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.27
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subs...
- Affected:
- up to 5.7.27
- Fixed in:
- 5.7.27
- Disclosed:
- Jul 17, 2024
CVE-2024-5703 on NVD →
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization
medium
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscribe...
- CVSS:
- 4.3
- Affected:
- up to 5.7.26
- Fixed in:
- 5.7.27
- Disclosed:
- Jul 16, 2024
CVE-2024-5703 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.26
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of su...
- Affected:
- up to 5.7.26
- Fixed in:
- 5.7.26
- Disclosed:
- Jul 2, 2024
CVE-2024-6172 on NVD →
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe
critical
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of suffici...
- CVSS:
- 9.8
- Affected:
- up to 5.7.25
- Fixed in:
- 5.7.26
- Disclosed:
- Jul 1, 2024
CVE-2024-6172 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.26
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
- Affected:
- up to 5.7.26
- Fixed in:
- 5.7.26
- Disclosed:
- Jun 26, 2024
CVE-2024-37252 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.24
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of su...
- Affected:
- up to 5.7.24
- Fixed in:
- 5.7.24
- Disclosed:
- Jun 21, 2024
CVE-2024-5756 on NVD →
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin
critical
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of suffici...
- CVSS:
- 9.8
- Affected:
- up to 5.7.23
- Fixed in:
- 5.7.24
- Disclosed:
- Jun 20, 2024
CVE-2024-5756 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.23
unknown
[en] The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticat...
- Affected:
- up to 5.7.23
- Fixed in:
- 5.7.23
- Disclosed:
- Jun 12, 2024
CVE-2024-4845 on NVD →
Icegram Express <= 5.7.22 - Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id]
high
The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 8.8
- Affected:
- up to 5.7.22
- Fixed in:
- 5.7.23
- Disclosed:
- Jun 11, 2024
CVE-2024-4845 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.14
unknown
[en] Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
- Affected:
- up to 5.7.14
- Fixed in:
- 5.7.14
- Disclosed:
- Jun 9, 2024
CVE-2024-31352 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.21
unknown
[en] The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for un...
- Affected:
- up to 5.7.21
- Fixed in:
- 5.7.21
- Disclosed:
- Jun 5, 2024
CVE-2024-4295 on NVD →
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
critical
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthe...
- CVSS:
- 9.8
- Affected:
- up to 5.7.20
- Fixed in:
- 5.7.21
- Disclosed:
- Jun 4, 2024
CVE-2024-4295 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.18
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possib...
- Affected:
- up to 5.7.18
- Fixed in:
- 5.7.18
- Disclosed:
- May 23, 2024
CVE-2024-3626 on NVD →
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization
medium
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible fo...
- CVSS:
- 4.3
- Affected:
- up to 5.7.17
- Fixed in:
- 5.7.18
- Disclosed:
- May 22, 2024
CVE-2024-3626 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.20
unknown
[en] The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers,...
- Affected:
- up to 5.7.20
- Fixed in:
- 5.7.20
- Disclosed:
- May 15, 2024
CVE-2024-4010 on NVD →
Email Subscribers by Icegram Express <= 5.7.19 - Missing Authorization in handle_ajax_request
high
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 5.7.19
- Fixed in:
- 5.7.20
- Disclosed:
- May 14, 2024
CVE-2024-4010 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.15
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user sup...
- Affected:
- up to 5.7.15
- Fixed in:
- 5.7.15
- Disclosed:
- May 2, 2024
CVE-2024-2876 on NVD →
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
critical
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied...
- CVSS:
- 9.8
- Affected:
- up to 5.7.14
- Fixed in:
- 5.7.15
- Disclosed:
- Apr 15, 2024
CVE-2024-2876 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.16
unknown
[en] The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it p...
- Affected:
- up to 5.7.16
- Fixed in:
- 5.7.16
- Disclosed:
- Apr 6, 2024
CVE-2024-2656 on NVD →
Email Subscribers & Newsletters <= 5.7.13 - Missing Authorization
medium
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 5.7.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.7.13
- Fixed in:
- 5.7.14
- Disclosed:
- Apr 5, 2024
CVE-2024-31352 on NVD →
Icegram Express <= 5.7.14 - Authenticated (Administrator+) Cross-Site Scripting via CSV import
medium
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 4.4
- Affected:
- up to 5.7.15
- Fixed in:
- 5.7.16
- Disclosed:
- Apr 5, 2024
CVE-2024-2656 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.12
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
- Affected:
- up to 5.7.12
- Fixed in:
- 5.7.12
- Disclosed:
- Mar 27, 2024
CVE-2024-22300 on NVD →
Email Subscribers & Newsletters <= 5.7.11 - Reflected Cross-Site Scripting via campaign_id
medium
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘campaign_id' parameter in versions up to, and including, 5.7.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.1
- Affected:
- up to 5.7.11
- Fixed in:
- 5.7.12
- Disclosed:
- Mar 26, 2024
CVE-2024-22300 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.5.3
unknown
[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: from n/a through 5.5.2.
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.3
- Disclosed:
- Nov 7, 2023
CVE-2022-45810 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.6.24
unknown
[en] The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to...
- Affected:
- up to 5.6.24
- Fixed in:
- 5.6.24
- Disclosed:
- Oct 20, 2023
CVE-2023-5414 on NVD →
Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read
critical
The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to othe...
- CVSS:
- 9.1
- Affected:
- up to 5.6.23
- Fixed in:
- 5.6.24
- Disclosed:
- Oct 11, 2023
CVE-2023-5414 on NVD →
Icegram Express <= 5.5.2 - Unauthenticated CSV Injection
medium
The Icegram Express plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.5.2. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable confi...
- CVSS:
- 6.5
- Affected:
- up to 5.5.2
- Fixed in:
- 5.5.3
- Disclosed:
- Feb 6, 2023
CVE-2022-45810 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.5.1
unknown
[en] The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
- Disclosed:
- Dec 12, 2022
CVE-2022-3981 on NVD →
Icegram Express <= 5.4.19 - Authenticated (Subscriber+) SQL Injection
high
The Icegram Express plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.19 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level privileges o...
- CVSS:
- 8.8
- Affected:
- up to 5.4.19
- Fixed in:
- 5.5.0
- Disclosed:
- Nov 21, 2022
CVE-2022-3981 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.3.2
unknown
[en] The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in pla...
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Mar 7, 2022
CVE-2022-0439 on NVD →
Email Subscribers & Newsletters <= 5.3.1 - Authenticated (or Cross-Site Request Forgery) Blind SQL Injection
high
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place fo...
- CVSS:
- 8.8
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Feb 11, 2022
CVE-2022-0439 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.5.6
unknown
Unauthenticated email forgery/spoofing vulnerability found by Alex Peña in WordPress Email Subscribers & Newsletters plugin (versions <= 4.5.5).
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Sep 10, 2020
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.5.6
unknown
[en] Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Sep 10, 2020
CVE-2020-5780 on NVD →
Email Subscribers & Newsletters <= 4.5.5 - Unauthenticated Email Forgery
medium
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
- CVSS:
- 5.3
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Sep 9, 2020
CVE-2020-5780 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.5.1
unknown
[en] Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Jul 17, 2020
CVE-2020-5767 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.5.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Jul 17, 2020
CVE-2020-5768 on NVD →
Icegram Email Subscribers & Newsletters <= 4.5.0 - Authenticated SQL Injection
medium
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
- CVSS:
- 4.9
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Jul 16, 2020
CVE-2020-5768 on NVD →
Icegram Email Subscribers & Newsletters Plugin for WordPress <= 4.5.0 - Cross-Site Request Forgery
high
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.5.0 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
- CVSS:
- 8.8
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Jul 13, 2020
CVE-2020-5767 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.3.1
unknown
[en] There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.1
- Disclosed:
- Jan 8, 2020
CVE-2019-20361 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
[en] The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 26, 2019
CVE-2019-19985 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
[en] The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 26, 2019
CVE-2019-19984 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
[en] The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 26, 2019
CVE-2019-19982 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
[en] The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_te...
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 26, 2019
CVE-2019-19980 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
[en] The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Dec 26, 2019
CVE-2019-19981 on NVD →
Email Subscribers & Newsletters < 4.3.1 - Unauthenticated Blind SQL Injection
high
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
- CVSS:
- 8.3
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.1
- Disclosed:
- Nov 13, 2019
CVE-2019-20361 on NVD →
Email Subscribers & Newsletters <= 4.2.2 - Unauthenticated Option Creation
medium
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
- CVSS:
- 6.5
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
CVE-2019-19982 on NVD →
Email Subscribers & Newsletters <= 4.2.2 - Missing Authorization
medium
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
- CVSS:
- 6.3
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
CVE-2019-19984 on NVD →
Email Subscribers & Newsletters <= 4.2.2 - Unauthenticated File Download w/ Information Disclosure
medium
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
- CVSS:
- 5.8
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
CVE-2019-19985 on NVD →
Email Subscribers & Newsletters <= 4.2.2 - Cross-Site Request Forgery on Settings
medium
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
- CVSS:
- 5.4
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
CVE-2019-19981 on NVD →
Email Subscribers & Newsletters <= 4.2.2 - Missing Authorization to Test Email
medium
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_em...
- CVSS:
- 4.3
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
CVE-2019-19980 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.2.3
unknown
Multiple security issues found by WordFence in WordPress Email Subscribers & Newsletters plugin (versions <=4.2.2).
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 13, 2019
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.1.7
unknown
[en] An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
- Disclosed:
- Jul 28, 2019
CVE-2019-14364 on NVD →
Email Subscribers & Newsletters <= 4.1.7 - SQL Injection
critical
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- CVSS:
- 9.8
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Jul 22, 2019
CVE-2019-13569 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 4.1.8
unknown
[en] A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Jul 19, 2019
CVE-2019-13569 on NVD →
Email Subscribers & Newsletters <= 4.1.6 - Cross-Site Scripting
medium
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
- CVSS:
- 6.1
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- Jul 12, 2019
CVE-2019-14364 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 3.5.0
unknown
[en] Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Jun 26, 2018
CVE-2018-0602 on NVD →
Email Subscribers & Newsletters <= 3.4.12 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 3.4.12
- Fixed in:
- 3.5.0
- Disclosed:
- May 28, 2018
CVE-2018-0602 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 3.4.8
unknown
[en] An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Jan 26, 2018
CVE-2018-6015 on NVD →
Email Subscribers & Newsletters <= 3.4.7 - Unauthenticated Subscriber Download
high
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
- CVSS:
- 7.5
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.8
- Disclosed:
- Jan 24, 2018
CVE-2018-6015 on NVD →
Email Subscribers & Newsletters < 2.9.1 - Cross-Site Scripting
medium
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 2.9.1 via the following parameters: 1) 'search' and 'es_mail_group' parameters in sendmail.php 2) 'search', 'sts', and 'cnt' parameters in view-subscriber-show.php 3) 'pagemail' parameter in sentmail-previe...
- CVSS:
- 6.1
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 10, 2015
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 2.9.1
unknown
This plugin is prone to a cross site scripting and SQL injection vulnerabilities. Because of them, attackers can inject arbitrary HTML or JS code or execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 10, 2015
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 2.9.1
unknown
The Email Subscribers & Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 2.9.1 via the following parameters: 1) 'search' and 'es_mail_group' parameters in sendmail.php 2) 'search', 'sts', and 'cnt' parameters in view-subscriber-show.php 3) 'pagemail' parameter in sentmail-previe...
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 10, 2015
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.7.50
unknown
- Affected:
- up to 5.7.50
- Fixed in:
- 5.7.50
CVE-2025-0671 on NVD →
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 5.3.2
unknown
The plugin lacks both authentication and nonce checks in its `es_dismiss_admin_notice` function, allowing an external attacker to set arbitrary plugin options to "yes".
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce [email-subscribers] < 2.9.1
unknown
The Email Subscribers & Newsletters – Simple and Effective Email Marketing WordPress Plugin WordPress plugin was affected by a Multiple XSS & SQLi security vulnerability.
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1