plugin

Sendpress Vulnerabilities

21 known security issues reported for the Sendpress WordPress plugin. Most recent disclosed Jun 13, 2024.

1 high 7 medium

Running Sendpress on your site? Check whether your installed version is affected.

Scan your site free

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Jun 13, 2024

CVE-2023-35040 on NVD →

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Apr 8, 2024

CVE-2024-1588 on NVD →

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Apr 8, 2024

CVE-2024-1589 on NVD →

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions.

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Nov 14, 2023

CVE-2023-47517 on NVD →

SendPress Newsletters <= 1.23.11.6 - Reflected Cross-Site Scripting

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.23.11.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 1.23.11.6
Fixed in:
1.24.8.19
Disclosed:
Nov 7, 2023

CVE-2023-47517 on NVD →

SendPress Newsletters [sendpress] < 1.23.11.6 (closed)

unknown

[en] The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c...

Affected:
up to 1.23.11.6
Fixed in:
1.23.11.6
Disclosed:
Nov 7, 2023

CVE-2023-5660 on NVD →

SendPress Newsletters <= 1.22.3.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...

CVSS:
6.4
Affected:
up to 1.22.3.31
Fixed in:
1.23.11.6
Disclosed:
Nov 6, 2023

CVE-2023-5660 on NVD →

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Oct 10, 2023

CVE-2023-41730 on NVD →

SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.

Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Oct 2, 2023

CVE-2023-41729 on NVD →

SendPress Newsletters <= 1.23.11.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.11.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...

CVSS:
4.4
Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Sep 5, 2023

CVE-2023-41729 on NVD →

SendPress Newsletters <= 1.23.11.6 - Cross-Site Request Forgery

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.11.6. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...

CVSS:
4.3
Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Sep 5, 2023

CVE-2023-41730 on NVD →

SendPress Newsletters <= 1.23.11.6 - Missing Authorization

medium

The SendPress Newsletters plugin for WordPress is vulnerable to unauthorized modification of due to a missing capability check on multiple REST routes that initiate cron execution in versions up to, and including, 1.23.11.6. This makes it possible for unauthenticated attackers to run the plugin's cron function.

CVSS:
5.3
Affected:
up to 1.23.11.6
Fix:
No patched version reported
Disclosed:
Aug 11, 2023

CVE-2023-35040 on NVD →

SendPress Newsletters < 1.20.7.13 - Authenticated Stored Cross-Site Scripting

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.20.6.08 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 1.20.7.13
Fixed in:
1.20.7.13
Disclosed:
Jul 13, 2020

SendPress Newsletters [sendpress] < 1.20.7.13 (closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress SendPress Newsletters plugin (versions <= 1.20.7.10).

Affected:
up to 1.20.7.13
Fixed in:
1.20.7.13
Disclosed:
Jul 13, 2020

SendPress Newsletters [sendpress] < 1.20.7.13 (closed)

unknown

The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.20.6.08 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...

Affected:
up to 1.20.7.13
Fixed in:
1.20.7.13
Disclosed:
Jul 13, 2020

SendPress Newsletters [sendpress] < 1.2 (closed)

unknown

[en] The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 26, 2019

CVE-2015-9448 on NVD →

SendPress Newsletters < 1.2 - Authenticated SQL Injection

high

The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Jul 23, 2015

CVE-2015-9448 on NVD →

SendPress Newsletters < 1.2 - Cross-Site Scripting

medium

The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subscriberID’ parameters in versions up to, and including, 1.1.7.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 1.1.7.21
Fixed in:
1.2
Disclosed:
Jul 23, 2015

SendPress Newsletters [sendpress] < 1.2 (closed)

unknown

The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subscriberID’ parameters in versions up to, and including, 1.1.7.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Jul 23, 2015

SendPress Newsletters [sendpress] < 1.2 (closed)

unknown

Because of this vulnerability, authenticated administrators can execute arbitrary SQL commands or inject HTML or JavaScript. Upgrade the plugin.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Jul 23, 2015

SendPress Newsletters [sendpress] < 1.20.7.13 (closed)

unknown

Multiple Stored Cross-Site Scripting within SendPress Newsletter Settings due to improper input sanitation. The vulnerable fields are: - From Name - From Email - Where to send Test Email

Affected:
up to 1.20.7.13
Fixed in:
1.20.7.13

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database