plugin

Woocommerce Follow Up Emails Vulnerabilities

4 known security issues reported for the Woocommerce Follow Up Emails WordPress plugin. Most recent disclosed May 24, 2023.

1 critical 1 high 2 medium

Running Woocommerce Follow Up Emails on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Follow-Up Emails <= 4.9.50 - Authenticated (Follow-up emails manager+) SQL Injection

high

The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.50 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with follow-up emai...

CVSS:
7.2
Affected:
up to 4.9.50
Fixed in:
4.9.51
Disclosed:
May 24, 2023

CVE-2023-33330 on NVD →

WooCommerce Follow-Up Emails <= 4.9.40 - Authenticated Arbitrary File Upload in Template Editing

critical

The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the template editing functionality in versions up to, and including, 4.9.40. This makes it possible for authenticated attackers, with Follow-Up Emails Manager permissions and above, to up...

CVSS:
9.9
Affected:
up to 4.9.40
Fixed in:
4.9.50
Disclosed:
May 22, 2023

CVE-2023-33318 on NVD →

WooCommerce Follow-Up Emails <= 4.9.40 - Reflected Cross-Site Scripting

medium

The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 4.9.40
Fixed in:
4.9.50
Disclosed:
May 22, 2023

CVE-2023-33319 on NVD →

WooCommerce Follow-Up Emails <= 4.9.40 - Cross-Site Request Forgery

medium

The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.40. This is due to missing or incorrect nonce validation in functions called via certain AJAX actions. This makes it possible for unauthenticated attackers to perform unauthorized acti...

CVSS:
4.3
Affected:
up to 4.9.40
Fixed in:
4.9.50
Disclosed:
May 22, 2023

CVE-2023-33316 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database