plugin

Wp Ses Vulnerabilities

3 known security issues reported for the Wp Ses WordPress plugin. Most recent disclosed Apr 17, 2023.

2 medium

Running Wp Ses on your site? Check whether your installed version is affected.

Scan your site free

guzzlehttp/psr7 < 1.9.1 & 2.4.5 - Interpretation Conflict

medium

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild wi...

CVSS:
5.3
Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Apr 17, 2023

CVE-2023-29197 on NVD →

WP Offload SES Lite [wp-ses] < 1.4.5

unknown

[en] The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling...

Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Jul 6, 2021

CVE-2021-24494 on NVD →

WP Offload SES Lite <= 1.4.4 - Stored Cross-Site Scripting

medium

The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a con...

CVSS:
5.4
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Jun 29, 2021

CVE-2021-24494 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database