VYPR

Wp Email Users

by Techspawn

CVEs (1)

  • CVE-2021-24959HigMar 14, 2022
    risk 0.57cvss 8.8epss 0.02

    The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.