plugin

Omnisend Connect Vulnerabilities

4 known security issues reported for the Omnisend Connect WordPress plugin. Most recent disclosed Jun 26, 2026.

1 high 3 medium

Running Omnisend Connect on your site? Check whether your installed version is affected.

Scan your site free

Email Marketing for WooCommerce by Omnisend <= 1.19.0 - Missing Authorization

medium

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 1.19.0
Fixed in:
1.19.1
Disclosed:
Jun 26, 2026

CVE-2026-57632 on NVD →

Omnisend for WooCommerce <= 1.18.0 - Unauthenticated Omnisend Account Takeover via Predictable Connect Token

high

The Omnisend for WooCommerce plugin for WordPress is vulnerable to an unauthenticated account takeover via insufficiently random values in versions up to, and including, 1.18.0. This is due to the generate_install_url() function deriving the OAuth connect token solely from the Unix timestamp at page-load time (hash('sh...

CVSS:
7.5
Affected:
up to 1.18.0
Fixed in:
1.18.1
Disclosed:
May 13, 2026

CVE-2026-42668 on NVD →

Email Marketing for WooCommerce by Omnisend <= 1.14.3 - Cross-Site Request Forgery

medium

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.14.3. This is due to missing or incorrect nonce validation on the 'log_options' action. This makes it possible for unauthenticated attackers to enable logging via a forged...

CVSS:
4.3
Affected:
up to 1.14.3
Fixed in:
1.14.4
Disclosed:
Apr 11, 2024

CVE-2024-32101 on NVD →

Email Marketing for WooCommerce by Omnisend <= 1.13.8 - Sensitive Information Exposure

medium

The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the status REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive user information.

CVSS:
5.3
Affected:
up to 1.13.8
Fixed in:
1.13.9
Disclosed:
Nov 7, 2023

CVE-2023-47244 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database