Kadence WooCommerce Email Designer <= 1.5.19 - Unauthenticated Privilege Escalation
critical
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.19. This makes it possible for unauthenticated attackers to elevate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 1.5.19
- Fixed in:
- 1.5.19.1
- Disclosed:
- Aug 4, 2026
CVE-2026-28005 on NVD →
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.18
unknown
[en] The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 1.5.18
- Fixed in:
- 1.5.18
- Disclosed:
- Dec 2, 2025
CVE-2025-13387 on NVD →
Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scripting
high
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 7.2
- Affected:
- up to 1.5.17
- Fixed in:
- 1.5.18
- Disclosed:
- Dec 1, 2025
CVE-2025-13387 on NVD →
Kadence WooCommerce Email Designer <= 1.5.16 - Authenticated (Shop Manager+) Arbitrary Options Update
high
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to insufficient input validation on the import_woomail() function in all versions up to, and including, 1.5.16. This makes it possible for authenticated attackers, wit...
- CVSS:
- 7.2
- Affected:
- up to 1.5.16
- Fixed in:
- 1.5.17
- Disclosed:
- Aug 14, 2025
CVE-2025-54697 on NVD →
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.17
unknown
[en] Incorrect Privilege Assignment vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Privilege Escalation. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.16.
- Affected:
- up to 1.5.17
- Fixed in:
- 1.5.17
- Disclosed:
- Aug 14, 2025
CVE-2025-54697 on NVD →
Kadence WooCommerce Email Designer <= 1.5.14 - Authenticated (Admin+) Arbitrary File Upload
high
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.14. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected s...
- CVSS:
- 7.2
- Affected:
- up to 1.5.14
- Fixed in:
- 1.5.15
- Disclosed:
- Apr 16, 2025
CVE-2025-39557 on NVD →
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.15
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.
- Affected:
- up to 1.5.15
- Fixed in:
- 1.5.15
- Disclosed:
- Apr 16, 2025
CVE-2025-39557 on NVD →
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.12
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.
- Affected:
- up to 1.5.12
- Fixed in:
- 1.5.12
- Disclosed:
- Nov 6, 2023
CVE-2023-47186 on NVD →
Kadence WooCommerce Email Designer <= 1.5.11 - Cross-Site Request Forgery
medium
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.11. This is due to missing or incorrect nonce validation on the ajax_reset() and ajax_send_email() functions. This makes it possible for unauthenticated attackers to send tes...
- CVSS:
- 4.3
- Affected:
- up to 1.5.11
- Fixed in:
- 1.5.12
- Disclosed:
- Nov 2, 2023
CVE-2023-47186 on NVD →
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.12
unknown
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.11. This is due to missing or incorrect nonce validation on the ajax_reset() and ajax_send_email() functions. This makes it possible for unauthenticated attackers to send tes...
- Affected:
- up to 1.5.12
- Fixed in:
- 1.5.12
- Disclosed:
- Nov 2, 2023
Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.7
unknown
[en] The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Oct 25, 2022
CVE-2022-3335 on NVD →
Kadence WooCommerce Email Designer <= 1.5.6 - PHP Object Injection
high
The Kadence WooCommerce Email Designer for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.6 via deserialization of untrusted input via the 'raw' parameter in the import_woomail function. This allows administrator-level attackers or higher to inject a PHP Object. No POP chain appea...
- CVSS:
- 7.2
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.7
- Disclosed:
- Sep 30, 2022
CVE-2022-3335 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database