VYPR

MailPress

by WordPress

CVEs (2)

  • CVE-2022-1843MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.01

    The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

  • CVE-2026-18436MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign//restore-revision/<revision_id>). The route in the vulnerable range was…