Vulnerabilities > Mailpoet

DATE CVE VULNERABILITY TITLE RISK
2020-06-02 CVE-2019-11843 Cross-site Scripting vulnerability in Mailpoet
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
network
mailpoet CWE-79
4.3
2019-11-06 CVE-2018-20853 Unspecified vulnerability in Mailpoet Newsletters
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress.
network
low complexity
mailpoet
5.0
2014-08-26 CVE-2014-3907 Cross-Site Request Forgery (CSRF) vulnerability in Mailpoet Newsletters
Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
network
mailpoet CWE-352
6.8
2014-07-27 CVE-2014-4726 Security vulnerability in WordPress MailPoet Newsletters Plugin
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
network
low complexity
mailpoet
7.5
2014-07-27 CVE-2014-4725 Improper Authentication vulnerability in Mailpoet Newsletters
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
network
low complexity
mailpoet CWE-287
7.5