plugin

Mailster Vulnerabilities

13 known security issues reported for the Mailster WordPress plugin. Most recent disclosed Jul 22, 2026.

1 critical 2 high 3 medium

Running Mailster on your site? Check whether your installed version is affected.

Scan your site free

Mailster - Email Newsletter Plugin for WordPress <= 4.1.17 - Authenticated (Editor+) Arbitrary File Upload

high

The Mailster WordPress Newsletter Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's...

CVSS:
7.2
Affected:
up to 4.1.17
Fixed in:
4.1.18
Disclosed:
Jul 22, 2026

CVE-2026-27064 on NVD →

Mailster WordPress Newsletter Plugin [mailster] < 4.1.14

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster allows Reflected XSS.This issue affects Mailster: from n/a through < 4.1.14.

Affected:
up to 4.1.14
Fixed in:
4.1.14
Disclosed:
Dec 18, 2025

CVE-2025-64203 on NVD →

Mailster < 4.1.14 - Reflected Cross-Site Scripting

medium

The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.1.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into per...

CVSS:
6.1
Affected:
up to 4.1.14
Fixed in:
4.1.14
Disclosed:
Oct 27, 2025

CVE-2025-64203 on NVD →

Mailster WordPress Newsletter Plugin [mailster] < 4.0.10

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.9.

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
Jul 22, 2024

CVE-2024-37433 on NVD →

Mailster <= 4.0.9 - Reflected Cross-Site Scripting

medium

The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 4.0.9
Fixed in:
4.0.10
Disclosed:
Jun 28, 2024

CVE-2024-37433 on NVD →

Mailster WordPress Newsletter Plugin [mailster] < 4.0.7

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
May 17, 2024

CVE-2024-32523 on NVD →

Mailster <= 4.0.6 - Unauthenticated Local File Inclusion

critical

The Mailster - Email Newsletter Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. T...

CVSS:
9.8
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Apr 15, 2024

CVE-2024-32523 on NVD →

Mailster WordPress Newsletter Plugin [mailster] < 2.0.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Mar 29, 2024

CVE-2024-30503 on NVD →

Mailster <= 1.0.3 - Reflected Cross-Site Scripting

medium

The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 1.0.3
Fixed in:
2.0.0
Disclosed:
Mar 28, 2024

CVE-2024-30503 on NVD →

Mailster <= 2.4.5.1 - Stored Cross-Site Scripting

high

The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
7.2
Affected:
up to 2.4.5.1
Fixed in:
2.4.9
Disclosed:
Oct 14, 2020

Mailster WordPress Newsletter Plugin [mailster] < 2.4.9

unknown

Stored Cross-Site Scripting (XSS) vulnerability found by Thierry Viaccoz in WordPress Mailster plugin (versions <= 2.4.8).

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Oct 14, 2020

Mailster WordPress Newsletter Plugin [mailster] < 2.4.9

unknown

The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Oct 14, 2020

Mailster WordPress Newsletter Plugin [mailster] < 2.4.9

unknown

Mailster [1] is a newsletter plugin for WordPress. It allows to create, send and track the newsletter campaigns. Compass Security identified a stored Cross-Site Scripting (XSS) vulnerability affecting the administration interface. Successful exploitation requires no authentication and can be performed remotely. [...

Affected:
up to 2.4.9
Fixed in:
2.4.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database