plugin

Sender Net Automated Emails Vulnerabilities

5 known security issues reported for the Sender Net Automated Emails WordPress plugin. Most recent disclosed Jul 23, 2026.

3 medium

Running Sender Net Automated Emails on your site? Check whether your installed version is affected.

Scan your site free

Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 - Authenticated (Administrator+) SQL Injection

medium

The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.10.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

CVSS:
4.9
Affected:
up to 2.10.22
Fixed in:
2.10.23
Disclosed:
Jul 23, 2026

CVE-2026-59537 on NVD →

Sender &#8211; Newsletter, SMS and Email Marketing Automation for WooCommerce [sender-net-automated-emails] < 2.6.19

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.

Affected:
up to 2.6.19
Fixed in:
2.6.19
Disclosed:
Aug 26, 2024

CVE-2024-39657 on NVD →

Sender &#8211; Newsletter, SMS and Email Marketing Automation for WooCommerce [sender-net-automated-emails] < 2.6.16

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a throu...

Affected:
up to 2.6.16
Fixed in:
2.6.16
Disclosed:
Aug 12, 2024

CVE-2024-43126 on NVD →

Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.15 - Reflected Cross-Site Scripting

medium

The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.6.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 2.6.15
Fixed in:
2.6.16
Disclosed:
Aug 7, 2024

CVE-2024-43126 on NVD →

Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.18 - Cross-Site Request Forgery

medium

The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.18. This is due to missing or incorrect nonce validation on the senderHandleFormPost() function. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 2.6.18
Fixed in:
2.6.19
Disclosed:
Aug 1, 2024

CVE-2024-39657 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database