SendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Form Settings
SendPress Newsletters
Minimum safe version
1.24.8.19
Update to 1.24.8.19 or later to address 8 fixable vulnerabilities
Latest available1.26.1.20 ✓⚠ 5 vulnerabilities have no fix
Medium 6.1 Unfixed
2024-04-08≤ 1.23.11.6
Medium 6.8 Unfixed
2024-04-08≤ 1.23.11.6
SendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Settings
High 7.1
2023-11-14< 1.24.8.19
CVE-2023-47517
Medium 5.4
2024-12-13< 1.23.11.6
WordPress SendPress Newsletters Plugin <= 1.22.3.31 is vulnerable to Cross Site Scripting (XSS)
Medium 4.3 Unfixed
2023-10-10≤ 1.26.1.20
CVE-2023-41730
Medium 5.9 Unfixed
2023-10-02≤ 1.26.1.20
CVE-2023-41729
Medium 5.3 Unfixed
2024-06-13≤ 1.26.1.20
CVE-2023-35040
N/A
< 1.20.7.13
SendPress Newsletter < 1.20.7.13 - Authenticated Stored Cross-Site Scripting (XSS)
N/A
2015-07-23< 1.2
SendPress Newsletters < 1.2 - Cross-Site Scripting
N/A
2020-07-13< 1.20.7.13
SendPress Newsletters < 1.20.7.13 - Authenticated Stored Cross-Site Scripting
N/A
2015-07-23< 1.2
WordPress SendPress Plugin <= 1.1.7.21 - Authenticated SQL Injection
N/A
2020-07-13< 1.20.7.13
WordPress SendPress Newsletters plugin <= 1.20.7.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
High 8.8
2019-09-26< 1.2
CVE-2015-9448