plugin

Wp Mailster Vulnerabilities

13 known security issues reported for the Wp Mailster WordPress plugin. Most recent disclosed Jan 28, 2025.

2 high 11 medium

Running Wp Mailster on your site? Check whether your installed version is affected.

Scan your site free

WP Mailster <= 1.8.20.0 - Reflected Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.20.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 1.8.20.0
Fixed in:
1.8.21.0
Disclosed:
Jan 28, 2025

CVE-2025-24688 on NVD →

WP Mailster <= 1.8.17.0 - Unauthenticated Sensitive Information Exposure

medium

The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.17.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.8.17.0
Fixed in:
1.8.18.0
Disclosed:
Jan 6, 2025

CVE-2025-22303 on NVD →

WP Mailster <= 1.8.17.0 - Reflected Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 1.8.17.0
Fixed in:
1.8.18.0
Disclosed:
Dec 22, 2024

CVE-2025-24598 on NVD →

WP Mailster <= 1.8.17.0 - Cross-Site Request Forgery

medium

The WP Mailster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.17.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site ad...

CVSS:
4.3
Affected:
up to 1.8.17.0
Fixed in:
1.8.18.0
Disclosed:
Dec 11, 2024

CVE-2024-54355 on NVD →

WP Mailster <= 1.8.16.0 - Unauthenticated Sensitive Information Exposure

medium

The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Dec 7, 2024

CVE-2025-24567 on NVD →

WP Mailster <= 1.8.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

CVSS:
6.4
Affected:
up to 1.8.17.0
Fixed in:
1.8.18.0
Disclosed:
Dec 2, 2024

CVE-2024-11782 on NVD →

WP Mailster <= 1.8.16.0 - Authenticated (Contributor+) SQL Injection via orderby

high

The WP Mailster plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.16.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
8.8
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Dec 2, 2024

CVE-2024-53807 on NVD →

WP Mailster <= 1.8.16.0 - Missing Authorization

high

The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
7.5
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Dec 2, 2024

CVE-2024-53805 on NVD →

WP Mailster <= 1.8.16.0 - Missing Authorization

medium

The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
6.5
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Dec 2, 2024

CVE-2024-53803 on NVD →

WP Mailster <= 1.8.16.0 - Unauthenticated Information Exposure

medium

The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Dec 2, 2024

CVE-2024-53804 on NVD →

WP Mailster <= 1.8.16.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.8.16.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 1.8.16.0
Fixed in:
1.8.17.0
Disclosed:
Nov 23, 2024

CVE-2024-53737 on NVD →

WP Mailster <= 1.8.15.0 - Reflected Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.15.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 1.8.15.0
Fixed in:
1.8.16.0
Disclosed:
Nov 23, 2024

CVE-2025-24559 on NVD →

WP Mailster < 1.5.5 - Cross-Site Scripting

medium

The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mes' parameter found in the 'view/subscription/unsubscribe2.php' file in versions up to 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

CVSS:
6.1
Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Dec 5, 2017

CVE-2017-17451 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database