WP Mailster <= 1.8.20.0 - Reflected Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.20.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 1.8.20.0
- Fixed in:
- 1.8.21.0
- Disclosed:
- Jan 28, 2025
CVE-2025-24688 on NVD →
WP Mailster <= 1.8.17.0 - Unauthenticated Sensitive Information Exposure
medium
The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.17.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.8.17.0
- Fixed in:
- 1.8.18.0
- Disclosed:
- Jan 6, 2025
CVE-2025-22303 on NVD →
WP Mailster <= 1.8.17.0 - Reflected Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 1.8.17.0
- Fixed in:
- 1.8.18.0
- Disclosed:
- Dec 22, 2024
CVE-2025-24598 on NVD →
WP Mailster <= 1.8.17.0 - Cross-Site Request Forgery
medium
The WP Mailster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.17.0. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 1.8.17.0
- Fixed in:
- 1.8.18.0
- Disclosed:
- Dec 11, 2024
CVE-2024-54355 on NVD →
WP Mailster <= 1.8.16.0 - Unauthenticated Sensitive Information Exposure
medium
The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Dec 7, 2024
CVE-2025-24567 on NVD →
WP Mailster <= 1.8.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...
- CVSS:
- 6.4
- Affected:
- up to 1.8.17.0
- Fixed in:
- 1.8.18.0
- Disclosed:
- Dec 2, 2024
CVE-2024-11782 on NVD →
WP Mailster <= 1.8.16.0 - Authenticated (Contributor+) SQL Injection via orderby
high
The WP Mailster plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.16.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 8.8
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Dec 2, 2024
CVE-2024-53807 on NVD →
WP Mailster <= 1.8.16.0 - Missing Authorization
high
The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 7.5
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Dec 2, 2024
CVE-2024-53805 on NVD →
WP Mailster <= 1.8.16.0 - Missing Authorization
medium
The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 6.5
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Dec 2, 2024
CVE-2024-53803 on NVD →
WP Mailster <= 1.8.16.0 - Unauthenticated Information Exposure
medium
The WP Mailster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.16.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Dec 2, 2024
CVE-2024-53804 on NVD →
WP Mailster <= 1.8.16.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.8.16.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 1.8.16.0
- Fixed in:
- 1.8.17.0
- Disclosed:
- Nov 23, 2024
CVE-2024-53737 on NVD →
WP Mailster <= 1.8.15.0 - Reflected Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.8.15.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 1.8.15.0
- Fixed in:
- 1.8.16.0
- Disclosed:
- Nov 23, 2024
CVE-2025-24559 on NVD →
WP Mailster < 1.5.5 - Cross-Site Scripting
medium
The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mes' parameter found in the 'view/subscription/unsubscribe2.php' file in versions up to 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Dec 5, 2017
CVE-2017-17451 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database