Mailster - Email Newsletter Plugin for WordPress <= 4.1.17 - Authenticated (Editor+) Arbitrary File Upload
high
The Mailster WordPress Newsletter Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's...
- CVSS:
- 7.2
- Affected:
- up to 4.1.17
- Fixed in:
- 4.1.18
- Disclosed:
- Jul 22, 2026
CVE-2026-27064 on NVD →
Mailster WordPress Newsletter Plugin [mailster] < 4.1.14
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster allows Reflected XSS.This issue affects Mailster: from n/a through < 4.1.14.
- Affected:
- up to 4.1.14
- Fixed in:
- 4.1.14
- Disclosed:
- Dec 18, 2025
CVE-2025-64203 on NVD →
Mailster < 4.1.14 - Reflected Cross-Site Scripting
medium
The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 4.1.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into per...
- CVSS:
- 6.1
- Affected:
- up to 4.1.14
- Fixed in:
- 4.1.14
- Disclosed:
- Oct 27, 2025
CVE-2025-64203 on NVD →
Mailster WordPress Newsletter Plugin [mailster] < 4.0.10
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.9.
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- Jul 22, 2024
CVE-2024-37433 on NVD →
Mailster <= 4.0.9 - Reflected Cross-Site Scripting
medium
The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.10
- Disclosed:
- Jun 28, 2024
CVE-2024-37433 on NVD →
Mailster WordPress Newsletter Plugin [mailster] < 4.0.7
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.7
- Disclosed:
- May 17, 2024
CVE-2024-32523 on NVD →
Mailster <= 4.0.6 - Unauthenticated Local File Inclusion
critical
The Mailster - Email Newsletter Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. T...
- CVSS:
- 9.8
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.7
- Disclosed:
- Apr 15, 2024
CVE-2024-32523 on NVD →
Mailster WordPress Newsletter Plugin [mailster] < 2.0.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Mar 29, 2024
CVE-2024-30503 on NVD →
Mailster <= 1.0.3 - Reflected Cross-Site Scripting
medium
The Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 1.0.3
- Fixed in:
- 2.0.0
- Disclosed:
- Mar 28, 2024
CVE-2024-30503 on NVD →
Mailster <= 2.4.5.1 - Stored Cross-Site Scripting
high
The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 7.2
- Affected:
- up to 2.4.5.1
- Fixed in:
- 2.4.9
- Disclosed:
- Oct 14, 2020
Mailster WordPress Newsletter Plugin [mailster] < 2.4.9
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Thierry Viaccoz in WordPress Mailster plugin (versions <= 2.4.8).
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Oct 14, 2020
Mailster WordPress Newsletter Plugin [mailster] < 2.4.9
unknown
The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Oct 14, 2020
Mailster WordPress Newsletter Plugin [mailster] < 2.4.9
unknown
Mailster [1] is a newsletter plugin for WordPress. It allows to create, send and track the newsletter campaigns.
Compass Security identified a stored Cross-Site Scripting (XSS) vulnerability affecting the administration interface. Successful exploitation requires no authentication and can be performed remotely.
[...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database