Vulnerabilities and security researches forkadence-woocommerce-email-designer kadence-woocommerce-email-designer
Direction: descendingApr 17, 2025
Kadence WooCommerce Email Designer # CVE-2025-39557
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 16, 2025
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 07, 2024
Kadence WooCommerce Email Designer # CVE-2023-47186
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 06, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Kadence WooCommerce Email Designer # CVE-2022-3335
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 25, 2022
- Research Description
- The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable