Vulnerabilities and security researches formailjet-for-wordpress mailjet-for-wordpress
Direction: ascendingJun 07, 2024
Mailjet Email Marketing # fd135b6d9545f4f161ad80ad33bc776604759116
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 03, 2023
- Research Description
- Mailjet Email Marketing [mailjet-for-wordpress] < 5.3.1 Mailjet Email Marketing <= 5.3 - Authenticated (Admin+) Cross-Site Scripting The Mailjet Email Marketing plugin for WordPress is vulnerable to authenticated stored cross-site scripting in versions up to, and including, 5.3 via the 'mailjet_from_name' parameter. This allows authenticated attackers with administrator-level capabilities to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 5.3.1.
- Status
-
vulnerable
Oct 08, 2026
Mailjet Email Marketing # CVE-2026-39791
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 06, 2026
- Research Description
- Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
- Affected versions
-
max 6.2.3.
- Status
-
vulnerable