Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
email subscribers vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2018-0602
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions before 3.5.0 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Email Subscribers \\& Newsletters Project Email Subscribers \\& Newsletters
5
CVSSv2
CVE-2018-6015
An issue exists in the "Email Subscribers & Newsletters" plugin prior to 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscr...
Icegram Email Subscribers \\& Newsletters
5
CVSSv2
CVE-2020-5780
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated malicious user to conduct unauthenticated email forgery/spoofing.
Icegram Email Subscribers \\& Newsletters
4
CVSSv2
CVE-2019-19980
The WordPress plugin, Email Subscribers & Newsletters, prior to 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugi...
Icegram Email Subscribers \\& Newsletters
4.3
CVSSv2
CVE-2019-19981
The WordPress plugin, Email Subscribers & Newsletters, prior to 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
Icegram Email Subscribers \\& Newsletters
5
CVSSv2
CVE-2019-19982
The WordPress plugin, Email Subscribers & Newsletters, prior to 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
Icegram Email Subscribers \\& Newsletters
6.5
CVSSv2
CVE-2019-19984
The WordPress plugin, Email Subscribers & Newsletters, prior to 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
Icegram Email Subscribers \\& Newsletters
5
CVSSv2
CVE-2019-19985
The WordPress plugin, Email Subscribers & Newsletters, prior to 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Icegram Email Subscribers \\& Newsletters
1 Github repository
NA
CVE-2022-3981
The Icegram Express WordPress plugin prior to 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
Icegram Email Subscribers \\& Newsletters
6.5
CVSSv2
CVE-2022-0439
The Email Subscribers & Newsletters WordPress plugin prior to 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it...
Icegram Email Subscribers \\& Newsletters
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-2907
hardcoded
inject
CVE-2024-20359
CVE-2024-2467
CVE-2024-4077
CVE-2024-22391
camera
CVE-2024-20353
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »