plugin

Mail Masta Vulnerabilities

29 known security issues reported for the Mail Masta WordPress plugin. Most recent disclosed Sep 16, 2019.

2 critical 12 high

Running Mail Masta on your site? Check whether your installed version is affected.

Scan your site free

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

[en] The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Sep 16, 2019

CVE-2016-10956 on NVD →

Mail Masta <= 1.0 - SQL Injection via subscriber_email parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Mar 9, 2017

CVE-2017-6578 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6578 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6577 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6576 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6570 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6574 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6571 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6572 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6573 on NVD →

Mail Masta [mail-masta] <= 1.0 (closed)

unknown

[en] A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.

Affected:
up to 1.0
Fixed in:
1.0
Disclosed:
Mar 9, 2017

CVE-2017-6575 on NVD →

Mail Masta Plugin <= 1.0 - SQL Injection via filter_list

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Mar 5, 2017

CVE-2017-6574 on NVD →

Mail Masta <= 1.0 - SQL Injection via id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Mar 5, 2017

CVE-2017-6576 on NVD →

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

[en] A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 21, 2017

CVE-2017-6095 on NVD →

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

[en] A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 21, 2017

CVE-2017-6096 on NVD →

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

[en] A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 21, 2017

CVE-2017-6097 on NVD →

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

[en] A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 21, 2017

CVE-2017-6098 on NVD →

Mail Masta <= 1.0 - SQL Injection via list_id parameter

critical

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6095 on NVD →

Mail Masta <= 1.0 - SQL Injection via list_id parameter

high

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6098 on NVD →

Mail Masta <= 1.0 - SQL Injection via list_id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6577 on NVD →

Mail Masta <= 1.0 - SQL Injection via filter_list parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6572 on NVD →

Mail Masta <= 1.0 - SQL Injection via member_id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6575 on NVD →

Mail Masta <= 1.0 - SQL Injection via id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6573 on NVD →

Mail Masta <= 1.0 - SQL Injection via id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6571 on NVD →

Mail Masta <= 1.0 - SQL Injection via camp_id parameter

high

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6097 on NVD →

Mail Masta <= 1.0 - SQL Injection via filter_list parameter

high

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6096 on NVD →

Mail Masta <= 1.0 - SQL Injection via id parameter

high

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.

CVSS:
7.2
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 18, 2017

CVE-2017-6570 on NVD →

Mail Masta <= 1.0 - Local File Inclusion

critical

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Aug 23, 2016

CVE-2016-10956 on NVD →

Mail Masta [mail-masta] <= 1.0 (unfixed + closed)

unknown

A Local File Inclusion vulnerability exists in WordPress Mail Masta Plugin 1.0 plugin. This vulnerability allows remote attackers to include arbitrary files on the server by "dynamic file inclusion" mechanism in Mail Masta Plugin. This plugin has been closed and is no longer available for download.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Aug 23, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database