Email Marketing for WooCommerce by Omnisend <= 1.19.0 - Missing Authorization
medium
The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized actio...
- CVSS:
- 4.3
- Affected:
- up to 1.19.0
- Fixed in:
- 1.19.1
- Disclosed:
- Jun 26, 2026
CVE-2026-57632 on NVD →
Omnisend for WooCommerce <= 1.18.0 - Unauthenticated Omnisend Account Takeover via Predictable Connect Token
high
The Omnisend for WooCommerce plugin for WordPress is vulnerable to an unauthenticated account takeover via insufficiently random values in versions up to, and including, 1.18.0. This is due to the generate_install_url() function deriving the OAuth connect token solely from the Unix timestamp at page-load time (hash('sh...
- CVSS:
- 7.5
- Affected:
- up to 1.18.0
- Fixed in:
- 1.18.1
- Disclosed:
- May 13, 2026
CVE-2026-42668 on NVD →
Email Marketing for WooCommerce by Omnisend <= 1.14.3 - Cross-Site Request Forgery
medium
The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.14.3. This is due to missing or incorrect nonce validation on the 'log_options' action. This makes it possible for unauthenticated attackers to enable logging via a forged...
- CVSS:
- 4.3
- Affected:
- up to 1.14.3
- Fixed in:
- 1.14.4
- Disclosed:
- Apr 11, 2024
CVE-2024-32101 on NVD →
Email Marketing for WooCommerce by Omnisend <= 1.13.8 - Sensitive Information Exposure
medium
The Email Marketing for WooCommerce by Omnisend plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the status REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive user information.
- CVSS:
- 5.3
- Affected:
- up to 1.13.8
- Fixed in:
- 1.13.9
- Disclosed:
- Nov 7, 2023
CVE-2023-47244 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database