plugin

Wysija Newsletters Vulnerabilities

29 known security issues reported for the Wysija Newsletters WordPress plugin. Most recent disclosed Nov 6, 2019.

1 critical 2 high 7 medium

Running Wysija Newsletters on your site? Check whether your installed version is affected.

Scan your site free

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.8.2 (closed)

unknown

[en] An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Nov 6, 2019

CVE-2018-20853 on NVD →

MailPoet Newsletters <= 2.8.1 - Spam Injection

medium

An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.

CVSS:
5.3
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Mar 14, 2018

CVE-2018-20853 on NVD →

MailPoet Newsletters <= 2.7.2 - SQL Injection

medium

The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
6.5
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Sep 11, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Sep 11, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Sep 11, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Sep 11, 2016

MailPoet Newsletters <= 2.7.2 - Reflected Cross-Site Scripting

medium

The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'encodedForm' parameter in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.5
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Sep 10, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'encodedForm' parameter in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Sep 10, 2016

MailPoet Newsletters <= 2.6.19 - Reflected Cross-Site Scripting

medium

The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ parameter in versions up to, and including, 2.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Feb 2, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)

unknown

The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ parameter in versions up to, and including, 2.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Feb 2, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)

unknown

This plugin is prone to reflected cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Feb 2, 2016

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)

unknown

This plugin is prone to swfupload cross site scripting vulnerability. Update the plugin.

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
May 15, 2015

MailPoet Newsletters <= 2.6.7 - Authorization Bypass

high

Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.

CVSS:
7.3
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Sep 21, 2014

CVE-2014-4726 on NVD →

MailPoet Newsletters (Previous) <= 2.6.10 - Cross-Site Request Forgery

medium

Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

CVSS:
6.3
Affected:
up to 2.6.11
Fixed in:
2.6.11
Disclosed:
Sep 21, 2014

CVE-2014-3907 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.11 (closed)

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

Affected:
up to 2.6.11
Fixed in:
2.6.11
Disclosed:
Aug 26, 2014

CVE-2014-3907 on NVD →

MailPoet Newsletters <= 2.6.6 - Arbitrary File Upload

critical

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

CVSS:
9.8
Affected:
up to 2.6.6
Fixed in:
2.6.7
Disclosed:
Aug 1, 2014

CVE-2014-4725 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.7 (closed)

unknown

[en] The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Jul 27, 2014

CVE-2014-4725 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.8 (closed)

unknown

[en] Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Jul 27, 2014

CVE-2014-4726 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.2.1 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated a...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Mar 24, 2014

CVE-2013-1408 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.3 (closed)

unknown

This WordPress Wysija Newsletters plugin is prone to multiple SQL-injection vulnerabilities. An attacker can compromise the application or exploit latent vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Feb 6, 2013

MailPoet Newsletters <= 2.2 - Multiple SQL Injections

high

Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attacke...

CVSS:
7.2
Affected:
up to 2.2
Fixed in:
2.2.1
Disclosed:
Feb 3, 2013

CVE-2013-1408 on NVD →

MailPoet Newsletters (Previous) <= 2.1.6 - Cross-Site Scripting

medium

The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim...

CVSS:
6.1
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Nov 22, 2012

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)

unknown

The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim...

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Nov 22, 2012

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)

unknown

The MailPoet Newsletters (Previous) WordPress plugin was affected by a swfupload Cross-Site Scripting security vulnerability.

Affected:
up to 2.1.7
Fixed in:
2.1.7

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

Changelog states: &quot;Fixed SQL injection vulnerability (Thanks to Force Interactive)&quot;

Affected:
up to 2.7.3
Fixed in:
2.7.3

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)

unknown

The MailPoet Newsletters (Previous) WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.7.3
Fixed in:
2.7.3

MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)

unknown

The MailPoet Newsletters (Previous) WordPress plugin was affected by an Unauthenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.7
Fixed in:
2.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database