VYPR

MailPoet Newsletters

by WordPress

CVEs (3)

  • CVE-2014-4725Jul 27, 2014
    risk 0.08cvss epss 0.60

    The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in…

  • CVE-2014-3907Aug 26, 2014
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

  • CVE-2014-4726Jul 27, 2014
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.