Freshmail <= 1.5.8 - Multiple SQL Injections
critical
The Freshmail plugin for WordPress is vulnerable to Multiple SQL Injections via the 'include/wp_ajax_fm_form.php' and 'include/wp_ajax_fm_form.php' in versions up to, and including, 1.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...
- CVSS:
- 9.8
- Affected:
- up to 1.5.8
- Fixed in:
- 1.6
- Disclosed:
- May 6, 2015
Freshmail for WordPress <= 1.5.8 - SQL Injection
high
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
- CVSS:
- 8.8
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- May 6, 2015
CVE-2015-9496 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database