VYPR

Email Subscribers \& Newsletters

by Icegram

Source repositories

CVEs (28)

  • CVE-2024-12568MedJan 13, 2025
    risk 0.31cvss 4.8epss 0.00

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-12567MedJan 13, 2025
    risk 0.31cvss 4.8epss 0.00

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-12566MedJan 13, 2025
    risk 0.31cvss 4.8epss 0.00

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed…

  • CVE-2024-11636MedJan 13, 2025
    risk 0.31cvss 4.8epss 0.00

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2024-8254MedOct 2, 2024
    risk 0.28cvss 5.4epss 0.01

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to…

  • CVE-2019-19980MedDec 26, 2019
    risk 0.28cvss 4.3epss 0.01

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin…

  • CVE-2024-8771MedSep 26, 2024
    risk 0.21cvss 4.3epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions…

  • CVE-2024-5703MedJul 17, 2024
    risk 0.21cvss 4.3epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible…

Page 2 of 2