plugin

Knews Vulnerabilities

6 known security issues reported for the Knews WordPress plugin. Most recent disclosed Apr 13, 2018.

1 critical 1 high 4 medium

Running Knews on your site? Check whether your installed version is affected.

Scan your site free

Knews Multilingual Newsletters <= 1.1.0 - Reflected Cross-Site Scripting

medium

The Knews Multilingual Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ff’ parameter in versions up to, and including,1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Apr 13, 2018

Knews Multilingual Newsletters Plugin <= 1.7.0 - SQL Injection

critical

The Knews Multilingual Newsletters plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenti...

CVSS:
9.8
Affected:
up to 1.7.0
Fixed in:
1.7.1
Disclosed:
Mar 16, 2015

Knews 1.2.5 - Multilingual Newsletters Cross-Site Request Forgery

medium
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Aug 1, 2014

Knews 1.2.5 - Unspecified XSS

medium
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Aug 1, 2014

Knews 1.1.0 - wysiwyg/fontpicker/index.php ff Parameter XSS

medium
Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Aug 1, 2014

Knews Multilingual Newsletters < 1.2.6 - Cross-Site Request Forgery

high

The Knews Multilingual Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the several functions. This makes it possible for unauthenticated attackers to inject SQL queries via a forged request gran...

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Dec 12, 2012

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database