FreshMail For WordPress [freshmail-integration] <= 2.3.2 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through 2.3.2.
- Affected:
- up to 2.3.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 31, 2024
CVE-2024-22304 on NVD →
FreshMail For WordPress <= 2.3.2 - Cross-Site Request Forgery
medium
The FreshMail For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.2. This is due to missing nonce validation function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a sit...
- CVSS:
- 4.3
- Affected:
- up to 2.3.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 17, 2024
CVE-2024-22304 on NVD →
FreshMail For WordPress [freshmail-integration] <= 2.3.2 (unfixed + closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Borbis Media FreshMail For WordPress plugin <= 2.3.2 versions.
- Affected:
- up to 2.3.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 26, 2023
CVE-2023-46074 on NVD →
FreshMail For WordPress <= 2.3.2 - Reflected Cross-Site Scripting
medium
The FreshMail For WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'list_type' parameter in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 2.3.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 16, 2023
CVE-2023-46074 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database