plugin

Wemail Vulnerabilities

14 known security issues reported for the Wemail WordPress plugin. Most recent disclosed Jun 26, 2026.

8 medium

Running Wemail on your site? Check whether your installed version is affected.

Scan your site free

weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce <= 2.1.2 - Reflected Cross-Site Scripting

medium

The weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...

CVSS:
6.1
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 26, 2026

CVE-2026-57322 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 2.0.8

unknown

[en] The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()` callback only validating the `X-WP-Nonce` header without...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Feb 21, 2026

CVE-2025-14339 on NVD →

weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion

medium

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()` callback only validating the `X-WP-Nonce` header without check...

CVSS:
6.5
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Feb 20, 2026

CVE-2025-14339 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 2.0.8

unknown

[en] The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST API trusting the `x-wemail-user` HTTP header to identify users without...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jan 20, 2026

CVE-2025-14348 on NVD →

weMail <= 2.0.7 - Insufficient Authorization via x-wemail-user Header to Sensitive Information Disclosure

medium

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST API trusting the `x-wemail-user` HTTP header to identify users without verif...

CVSS:
5.3
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Jan 19, 2026

CVE-2025-14348 on NVD →

weMail <= 1.14.13 - Unauthenticated Sensitive Information Exposure

medium

The weMail – Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to Sensitive Information Exposure via the users() function in all versions up to, and including, 1.14.13. This makes it possible for unauthenticated attackers to extract user ema...

CVSS:
5.3
Affected:
up to 1.14.13
Fixed in:
1.14.14
Disclosed:
May 7, 2025

CVE-2025-47540 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 1.14.14

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.

Affected:
up to 1.14.14
Fixed in:
1.14.14
Disclosed:
May 7, 2025

CVE-2025-47540 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 1.14.6

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs weMail allows Reflected XSS.This issue affects weMail: from n/a through 1.14.5.

Affected:
up to 1.14.6
Fixed in:
1.14.6
Disclosed:
Aug 18, 2024

CVE-2024-43238 on NVD →

weMail <= 1.14.5 - Reflected Cross-Site Scripting

medium

The weMail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
6.1
Affected:
up to 1.14.5
Fixed in:
1.14.6
Disclosed:
Aug 12, 2024

CVE-2024-43238 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 1.14.3

unknown

[en] Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.

Affected:
up to 1.14.3
Fixed in:
1.14.3
Disclosed:
Jun 11, 2024

CVE-2024-34822 on NVD →

weMail <= 1.14.2 - Missing Authorization to Notice Dismissal

medium

The weMail plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the connect_notice() function in versions up to, and including, 1.14.2. This makes it possible for unauthenticated attackers to dismiss notices.

CVSS:
5.3
Affected:
up to 1.14.2
Fixed in:
1.14.3
Disclosed:
May 15, 2024

CVE-2024-34822 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 1.14.1
Fixed in:
1.14.2
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 1.14.1
Fixed in:
1.14.2
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

weMail: Email Marketing, Email Automation, Newsletters, Subscribers &amp; eCommerce Email Optins [wemail] < 1.14.2

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.14.2
Fixed in:
1.14.2

CVE-2022-47150 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database