plugin

Kadence Woocommerce Email Designer Vulnerabilities

12 known security issues reported for the Kadence Woocommerce Email Designer WordPress plugin. Most recent disclosed Aug 4, 2026.

1 critical 4 high 1 medium

Running Kadence Woocommerce Email Designer on your site? Check whether your installed version is affected.

Scan your site free

Kadence WooCommerce Email Designer <= 1.5.19 - Unauthenticated Privilege Escalation

critical

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.19. This makes it possible for unauthenticated attackers to elevate their privileges.

CVSS:
9.8
Affected:
up to 1.5.19
Fixed in:
1.5.19.1
Disclosed:
Aug 4, 2026

CVE-2026-28005 on NVD →

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.18

unknown

[en] The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 1.5.18
Fixed in:
1.5.18
Disclosed:
Dec 2, 2025

CVE-2025-13387 on NVD →

Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scripting

high

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
7.2
Affected:
up to 1.5.17
Fixed in:
1.5.18
Disclosed:
Dec 1, 2025

CVE-2025-13387 on NVD →

Kadence WooCommerce Email Designer <= 1.5.16 - Authenticated (Shop Manager+) Arbitrary Options Update

high

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to insufficient input validation on the import_woomail() function in all versions up to, and including, 1.5.16. This makes it possible for authenticated attackers, wit...

CVSS:
7.2
Affected:
up to 1.5.16
Fixed in:
1.5.17
Disclosed:
Aug 14, 2025

CVE-2025-54697 on NVD →

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.17

unknown

[en] Incorrect Privilege Assignment vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Privilege Escalation. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.16.

Affected:
up to 1.5.17
Fixed in:
1.5.17
Disclosed:
Aug 14, 2025

CVE-2025-54697 on NVD →

Kadence WooCommerce Email Designer <= 1.5.14 - Authenticated (Admin+) Arbitrary File Upload

high

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.14. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected s...

CVSS:
7.2
Affected:
up to 1.5.14
Fixed in:
1.5.15
Disclosed:
Apr 16, 2025

CVE-2025-39557 on NVD →

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.15

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.

Affected:
up to 1.5.15
Fixed in:
1.5.15
Disclosed:
Apr 16, 2025

CVE-2025-39557 on NVD →

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.12

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.

Affected:
up to 1.5.12
Fixed in:
1.5.12
Disclosed:
Nov 6, 2023

CVE-2023-47186 on NVD →

Kadence WooCommerce Email Designer <= 1.5.11 - Cross-Site Request Forgery

medium

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.11. This is due to missing or incorrect nonce validation on the ajax_reset() and ajax_send_email() functions. This makes it possible for unauthenticated attackers to send tes...

CVSS:
4.3
Affected:
up to 1.5.11
Fixed in:
1.5.12
Disclosed:
Nov 2, 2023

CVE-2023-47186 on NVD →

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.12

unknown

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.11. This is due to missing or incorrect nonce validation on the ajax_reset() and ajax_send_email() functions. This makes it possible for unauthenticated attackers to send tes...

Affected:
up to 1.5.12
Fixed in:
1.5.12
Disclosed:
Nov 2, 2023

Kadence WooCommerce Email Designer [kadence-woocommerce-email-designer] < 1.5.7

unknown

[en] The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Oct 25, 2022

CVE-2022-3335 on NVD →

Kadence WooCommerce Email Designer <= 1.5.6 - PHP Object Injection

high

The Kadence WooCommerce Email Designer for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.6 via deserialization of untrusted input via the 'raw' parameter in the import_woomail function. This allows administrator-level attackers or higher to inject a PHP Object. No POP chain appea...

CVSS:
7.2
Affected:
up to 1.5.6
Fixed in:
1.5.7
Disclosed:
Sep 30, 2022

CVE-2022-3335 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database