Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 - Authenticated (Administrator+) SQL Injection
medium
The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.10.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- CVSS:
- 4.9
- Affected:
- up to 2.10.22
- Fixed in:
- 2.10.23
- Disclosed:
- Jul 23, 2026
CVE-2026-59537 on NVD →
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce [sender-net-automated-emails] < 2.6.19
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.
- Affected:
- up to 2.6.19
- Fixed in:
- 2.6.19
- Disclosed:
- Aug 26, 2024
CVE-2024-39657 on NVD →
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce [sender-net-automated-emails] < 2.6.16
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a throu...
- Affected:
- up to 2.6.16
- Fixed in:
- 2.6.16
- Disclosed:
- Aug 12, 2024
CVE-2024-43126 on NVD →
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.15 - Reflected Cross-Site Scripting
medium
The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.6.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 2.6.15
- Fixed in:
- 2.6.16
- Disclosed:
- Aug 7, 2024
CVE-2024-43126 on NVD →
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.18 - Cross-Site Request Forgery
medium
The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.18. This is due to missing or incorrect nonce validation on the senderHandleFormPost() function. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 2.6.18
- Fixed in:
- 2.6.19
- Disclosed:
- Aug 1, 2024
CVE-2024-39657 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database