plugin

Envialosimple Email Marketing Y Newsletters Gratis Vulnerabilities

11 known security issues reported for the Envialosimple Email Marketing Y Newsletters Gratis WordPress plugin. Most recent disclosed May 26, 2026.

1 high 5 medium

Running Envialosimple Email Marketing Y Newsletters Gratis on your site? Check whether your installed version is affected.

Scan your site free

EnvíaloSimple: Email Marketing y Newsletters <= 2.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

medium

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak...

CVSS:
4.9
Affected:
up to 2.4.5
Fixed in:
2.4.6
Disclosed:
May 26, 2026

CVE-2026-7618 on NVD →

EnvíaloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis] < 2.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvialoSimple EnvíaloSimple allows Reflected XSS.This issue affects EnvíaloSimple: from n/a through 2.2.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Apr 18, 2024

CVE-2024-32587 on NVD →

EnvíaloSimple: Email Marketing y Newsletters <= 2.2 - Reflected Cross-Site Scripting

medium

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 2.2
Fixed in:
2.3
Disclosed:
Apr 16, 2024

CVE-2024-32587 on NVD →

EnvíaloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis] < 2.4

unknown

[en] The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it possible for unauthenticated attackers to upload malicious fil...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 9, 2024

CVE-2024-2125 on NVD →

EnvíaloSimple: Email Marketing y Newsletters <= 2.3 - Cross-Site Request Forgery to Arbitrary File Upload

high

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it possible for unauthenticated attackers to upload malicious files vi...

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Apr 1, 2024

CVE-2024-2125 on NVD →

EnvíaloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis] < 2.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Mar 26, 2024

CVE-2023-51416 on NVD →

EnvíaloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis] < 2.2

unknown

[en] Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1.

Affected:
up to 2.2
Fixed in:
2.2
Disclosed:
Dec 29, 2023

CVE-2023-51414 on NVD →

EnvíaloSimple <= 2.1 Unauthenticated PHP Object Injection

medium

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If...

CVSS:
6.5
Affected:
up to 2.1
Fixed in:
2.2
Disclosed:
Dec 27, 2023

CVE-2023-51414 on NVD →

EnvíaloSimple <= 2.2 - Cross-Site Request Forgery

medium

The EnvíaloSimple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 2.2
Fixed in:
2.3
Disclosed:
Dec 27, 2023

CVE-2023-51416 on NVD →

EnvíaloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis] < 1.98

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2) Ad...

Affected:
up to 1.98
Fixed in:
1.98
Disclosed:
Jul 2, 2014

CVE-2014-4527 on NVD →

EnvialoSimple: Email Marketing y Newsletters < 1.98 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2) Adminis...

CVSS:
6.1
Affected:
up to 1.97
Fixed in:
1.98
Disclosed:
May 28, 2014

CVE-2014-4527 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database