plugin

Welcome Email Editor Vulnerabilities

6 known security issues reported for the Welcome Email Editor WordPress plugin. Most recent disclosed Dec 9, 2024.

2 medium

Running Welcome Email Editor on your site? Check whether your installed version is affected.

Scan your site free

Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7

unknown

[en] Missing Authorization vulnerability in David Vongries Welcome Email Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through 5.0.6.

Affected:
up to 5.0.7
Fixed in:
5.0.7
Disclosed:
Dec 9, 2024

CVE-2023-47756 on NVD →

Swift SMTP <= 5.0.6 - Cross-Site Request Forgery

medium

The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...

CVSS:
4.3
Affected:
up to 5.0.6
Fixed in:
5.0.7
Disclosed:
Jan 8, 2024

Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7

unknown

The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...

Affected:
up to 5.0.7
Fixed in:
5.0.7
Disclosed:
Jan 8, 2024

Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7

unknown

Update the WordPress Welcome Email Editor plugin to the latest available version (at least 5.0.7). ajax_handler discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Welcome Email Editor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted a...

Affected:
up to 5.0.7
Fixed in:
5.0.7
Disclosed:
Jan 8, 2024

Welcome Email Editor <= 5.0.5 - Missing Authorization via ajax_handler

medium

The Welcome Email Editor plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ajax_handler function in versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to send a variety of emails.

CVSS:
5.3
Affected:
up to 5.0.5
Fixed in:
5.0.6
Disclosed:
Nov 13, 2023

CVE-2023-47756 on NVD →

Swift SMTP (formerly Welcome Email Editor) [welcome-email-editor] < 5.0.7

unknown

The Swift SMTP (formerly Welcome Email Editor) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.6. This is due to missing or incorrect nonce validation on the ajax_handler() function. This makes it possible for unauthenticated attackers to send emails via a forg...

Affected:
up to 5.0.7
Fixed in:
5.0.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database