plugin

Email Users Vulnerabilities

14 known security issues reported for the Email Users WordPress plugin. Most recent disclosed Jun 13, 2022.

1 high 3 medium

Running Email Users on your site? Check whether your installed version is affected.

Scan your site free

Email Users [email-users] <= 4.8.8 (unfixed + closed)

unknown

[en] The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

Affected:
up to 4.8.8
Fix:
No patched version reported
Disclosed:
Jun 13, 2022

CVE-2022-1605 on NVD →

Email Users <= 4.8.8 - Arbitrary Settings Update via Cross-Site Request Forgery

high

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

CVSS:
8.8
Affected:
up to 4.8.8
Fix:
No patched version reported
Disclosed:
May 18, 2022

CVE-2022-1605 on NVD →

Email Users < 4.8.4 - Cross-Site Request Forgery

medium

The Email Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.8.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to send arbitrary bulk emails via a forged request granted they can trick a site admi...

CVSS:
4.3
Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Aug 15, 2016

Email Users [email-users] < 4.8.4 (closed)

unknown

The Email Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.8.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to send arbitrary bulk emails via a forged request granted they can trick a site admi...

Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Aug 15, 2016

Email Users [email-users] < 4.8.4 (closed)

unknown

Because of this vulnerability, attackers can send arbitrary (bulk) email messages to any address. Update the plugin.

Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Aug 1, 2016

Email Users <= 4.8.2 - Reflected Cross-Site Scripting

medium

The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 4.8.3
Fixed in:
4.8.3
Disclosed:
Jul 13, 2016

Email Users [email-users] < 4.8.3 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 4.8.3
Fixed in:
4.8.3
Disclosed:
Jul 13, 2016

Email Users [email-users] < 4.8.3 (closed)

unknown

The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 4.8.3
Fixed in:
4.8.3
Disclosed:
Jul 13, 2016

Email Users <= 4.7.5 - Reflected Cross Site Scripting

medium

The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_id’ parameter in versions up to, and including, 4.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...

CVSS:
5.3
Affected:
up to 4.7.6
Fixed in:
4.7.6
Disclosed:
Aug 10, 2015

Email Users [email-users] < 4.7.6 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 4.7.6
Fixed in:
4.7.6
Disclosed:
Aug 10, 2015

Email Users [email-users] < 4.7.6 (closed)

unknown

The email-users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_id’ parameter in versions up to, and including, 4.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...

Affected:
up to 4.7.6
Fixed in:
4.7.6
Disclosed:
Aug 10, 2015

Email Users [email-users] < 4.8.4 (closed)

unknown

The Email Users WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 4.8.4
Fixed in:
4.8.4

Email Users [email-users] < 4.8.4 (closed)

unknown

The Email Users WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.8.4
Fixed in:
4.8.4

Email Users [email-users] < 4.8.4 (closed)

unknown

The Email Users WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.8.4
Fixed in:
4.8.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database