Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7
unknown
[en] Missing Authorization vulnerability in David Vongries Welcome Email Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through 5.0.6.
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.7
- Disclosed:
- Dec 9, 2024
CVE-2023-47756 on NVD →
Swift SMTP <= 5.0.6 - Cross-Site Request Forgery
medium
The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...
- CVSS:
- 4.3
- Affected:
- up to 5.0.6
- Fixed in:
- 5.0.7
- Disclosed:
- Jan 8, 2024
Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7
unknown
The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.7
- Disclosed:
- Jan 8, 2024
Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7
unknown
Update the WordPress Welcome Email Editor plugin to the latest available version (at least 5.0.7).
ajax_handler discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Welcome Email Editor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted a...
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.7
- Disclosed:
- Jan 8, 2024
Welcome Email Editor <= 5.0.5 - Missing Authorization via ajax_handler
medium
The Welcome Email Editor plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ajax_handler function in versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to send a variety of emails.
- CVSS:
- 5.3
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.6
- Disclosed:
- Nov 13, 2023
CVE-2023-47756 on NVD →
Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7
unknown
The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database