plugin

Manage Notification Emails Vulnerabilities

4 known security issues reported for the Manage Notification Emails WordPress plugin. Most recent disclosed Jan 11, 2024.

1 high 1 medium

Running Manage Notification Emails on your site? Check whether your installed version is affected.

Scan your site free

Manage Notification E-mails [manage-notification-emails] < 1.8.6

unknown

[en] The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Jan 11, 2024

CVE-2023-6496 on NVD →

Manage Notification E-mails <= 1.8.5 - Missing Authorization

medium

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

CVSS:
5.3
Affected:
up to 1.8.5
Fixed in:
1.8.6
Disclosed:
Dec 8, 2023

CVE-2023-6496 on NVD →

Manage Notification E-mails [manage-notification-emails] < 1.8.3

unknown

[en] Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.

Affected:
up to 1.8.3
Fixed in:
1.8.3
Disclosed:
Nov 28, 2022

CVE-2022-34654 on NVD →

Manage Notification E-mails <= 1.8.2 - Cross-Site Request Forgery to Plugin Options Update

high

The Manage Notification E-mails plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to reset the plugin's settings, via forged r...

CVSS:
8.8
Affected:
up to 1.8.2
Fixed in:
1.8.3
Disclosed:
Sep 27, 2022

CVE-2022-34654 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database