SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 13, 2024
CVE-2023-35040 on NVD →
SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 8, 2024
CVE-2024-1588 on NVD →
SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 8, 2024
CVE-2024-1589 on NVD →
SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions.
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 14, 2023
CVE-2023-47517 on NVD →
SendPress Newsletters <= 1.23.11.6 - Reflected Cross-Site Scripting
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.23.11.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 6.1
- Affected:
- up to 1.23.11.6
- Fixed in:
- 1.24.8.19
- Disclosed:
- Nov 7, 2023
CVE-2023-47517 on NVD →
SendPress Newsletters [sendpress] < 1.23.11.6 (closed)
unknown
[en] The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c...
- Affected:
- up to 1.23.11.6
- Fixed in:
- 1.23.11.6
- Disclosed:
- Nov 7, 2023
CVE-2023-5660 on NVD →
SendPress Newsletters <= 1.22.3.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...
- CVSS:
- 6.4
- Affected:
- up to 1.22.3.31
- Fixed in:
- 1.23.11.6
- Disclosed:
- Nov 6, 2023
CVE-2023-5660 on NVD →
SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2023
CVE-2023-41730 on NVD →
SendPress Newsletters [sendpress] <= 1.23.11.6 (unfixed + closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 2, 2023
CVE-2023-41729 on NVD →
SendPress Newsletters <= 1.23.11.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.11.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2023
CVE-2023-41729 on NVD →
SendPress Newsletters <= 1.23.11.6 - Cross-Site Request Forgery
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.11.6. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2023
CVE-2023-41730 on NVD →
SendPress Newsletters <= 1.23.11.6 - Missing Authorization
medium
The SendPress Newsletters plugin for WordPress is vulnerable to unauthorized modification of due to a missing capability check on multiple REST routes that initiate cron execution in versions up to, and including, 1.23.11.6. This makes it possible for unauthenticated attackers to run the plugin's cron function.
- CVSS:
- 5.3
- Affected:
- up to 1.23.11.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 11, 2023
CVE-2023-35040 on NVD →
SendPress Newsletters < 1.20.7.13 - Authenticated Stored Cross-Site Scripting
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.20.6.08 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 1.20.7.13
- Fixed in:
- 1.20.7.13
- Disclosed:
- Jul 13, 2020
SendPress Newsletters [sendpress] < 1.20.7.13 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress SendPress Newsletters plugin (versions <= 1.20.7.10).
- Affected:
- up to 1.20.7.13
- Fixed in:
- 1.20.7.13
- Disclosed:
- Jul 13, 2020
SendPress Newsletters [sendpress] < 1.20.7.13 (closed)
unknown
The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.20.6.08 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...
- Affected:
- up to 1.20.7.13
- Fixed in:
- 1.20.7.13
- Disclosed:
- Jul 13, 2020
SendPress Newsletters [sendpress] < 1.2 (closed)
unknown
[en] The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Sep 26, 2019
CVE-2015-9448 on NVD →
SendPress Newsletters < 1.2 - Authenticated SQL Injection
high
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Jul 23, 2015
CVE-2015-9448 on NVD →
SendPress Newsletters < 1.2 - Cross-Site Scripting
medium
The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subscriberID’ parameters in versions up to, and including, 1.1.7.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 1.1.7.21
- Fixed in:
- 1.2
- Disclosed:
- Jul 23, 2015
SendPress Newsletters [sendpress] < 1.2 (closed)
unknown
The SendPress Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'listID' & 'subscriberID’ parameters in versions up to, and including, 1.1.7.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Jul 23, 2015
SendPress Newsletters [sendpress] < 1.2 (closed)
unknown
Because of this vulnerability, authenticated administrators can execute arbitrary SQL commands or inject HTML or JavaScript.
Upgrade the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Jul 23, 2015
SendPress Newsletters [sendpress] < 1.20.7.13 (closed)
unknown
Multiple Stored Cross-Site Scripting within SendPress Newsletter Settings due to improper input sanitation. The vulnerable fields are:
- From Name
- From Email
- Where to send Test Email
- Affected:
- up to 1.20.7.13
- Fixed in:
- 1.20.7.13
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database