plugin

Wp Mailup Vulnerabilities

4 known security issues reported for the Wp Mailup WordPress plugin. Most recent disclosed Mar 22, 2013.

2 medium

Running Wp Mailup on your site? Check whether your installed version is affected.

Scan your site free

MailUp newsletter sign-up form [wp-mailup] < 1.3.3 (closed)

unknown

[en] ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete f...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 22, 2013

CVE-2013-0731 on NVD →

MailUp newsletter sign-up form [wp-mailup] < 1.3.3 (closed)

unknown

[en] ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 22, 2013

CVE-2013-2640 on NVD →

MailUp newsletter sign-up form < 1.3.2 - Cross-Site Scripting

medium

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than...

CVSS:
6.4
Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Mar 15, 2013

CVE-2013-2640 on NVD →

MailUp newsletter sign-up form < 1.3.3 - Cross-Site Scripting

medium

ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete fix fo...

CVSS:
6.1
Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 13, 2013

CVE-2013-0731 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database