MailPoet Newsletters (Previous) [wysija-newsletters] < 2.8.2 (closed)
unknown
[en] An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Nov 6, 2019
CVE-2018-20853 on NVD →
MailPoet Newsletters <= 2.8.1 - Spam Injection
medium
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
- CVSS:
- 5.3
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Mar 14, 2018
CVE-2018-20853 on NVD →
MailPoet Newsletters <= 2.7.2 - SQL Injection
medium
The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...
- CVSS:
- 6.5
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 11, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 11, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 11, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 11, 2016
MailPoet Newsletters <= 2.7.2 - Reflected Cross-Site Scripting
medium
The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'encodedForm' parameter in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.5
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 10, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'encodedForm' parameter in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Sep 10, 2016
MailPoet Newsletters <= 2.6.19 - Reflected Cross-Site Scripting
medium
The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ parameter in versions up to, and including, 2.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Feb 2, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)
unknown
The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wysija-key’ parameter in versions up to, and including, 2.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Feb 2, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)
unknown
This plugin is prone to reflected cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Feb 2, 2016
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)
unknown
This plugin is prone to swfupload cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- May 15, 2015
MailPoet Newsletters <= 2.6.7 - Authorization Bypass
high
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
- CVSS:
- 7.3
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Sep 21, 2014
CVE-2014-4726 on NVD →
MailPoet Newsletters (Previous) <= 2.6.10 - Cross-Site Request Forgery
medium
Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
- CVSS:
- 6.3
- Affected:
- up to 2.6.11
- Fixed in:
- 2.6.11
- Disclosed:
- Sep 21, 2014
CVE-2014-3907 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.11 (closed)
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
- Affected:
- up to 2.6.11
- Fixed in:
- 2.6.11
- Disclosed:
- Aug 26, 2014
CVE-2014-3907 on NVD →
MailPoet Newsletters <= 2.6.6 - Arbitrary File Upload
critical
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
- CVSS:
- 9.8
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Aug 1, 2014
CVE-2014-4725 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.7 (closed)
unknown
[en] The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Jul 27, 2014
CVE-2014-4725 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.6.8 (closed)
unknown
[en] Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Jul 27, 2014
CVE-2014-4726 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.2.1 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated a...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Mar 24, 2014
CVE-2013-1408 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.3 (closed)
unknown
This WordPress Wysija Newsletters plugin is prone to multiple SQL-injection vulnerabilities. An attacker can compromise the application or exploit latent vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Feb 6, 2013
MailPoet Newsletters <= 2.2 - Multiple SQL Injections
high
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attacke...
- CVSS:
- 7.2
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Feb 3, 2013
CVE-2013-1408 on NVD →
MailPoet Newsletters (Previous) <= 2.1.6 - Cross-Site Scripting
medium
The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim...
- CVSS:
- 6.1
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Nov 22, 2012
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)
unknown
The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim...
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Nov 22, 2012
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.1.7 (closed)
unknown
The MailPoet Newsletters (Previous) WordPress plugin was affected by a swfupload Cross-Site Scripting security vulnerability.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
Changelog states: "Fixed SQL injection vulnerability (Thanks to Force Interactive)"
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7.3 (closed)
unknown
The MailPoet Newsletters (Previous) WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
MailPoet Newsletters (Previous) [wysija-newsletters] < 2.7 (closed)
unknown
The MailPoet Newsletters (Previous) WordPress plugin was affected by an Unauthenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database