N/A Closed
2024-01-10< 8.0.7
WordPress Email Newsletter Plugin <= 8.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
Minimum safe version
20.13.7
Update to 20.13.7 or later to address 5 fixable vulnerabilities
WordPress Email Newsletter Plugin <= 8.0.6 is vulnerable to Cross Site Request Forgery (CSRF)
Email Newsletter <= 8.0 - Sensitive Information Disclosure
Email Newsletter <= 20.13.6 - Reflected Cross-Site Scripting
Email Newsletter <= 8.0 - Information Disclosure
wpscan.com
Email newsletter <= 20.13.6 - Authenticated Cross-Site Scripting (XSS)
WordPress Email Newsletter Plugin 8.0 - Information Disclosure Vulnerability
WordPress Email Newsletter Plugin <= 20.13.6 - Cross Site Scripting
CVE-2015-9334