cleantalk
Vulnerabilities and Security Researches

weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin, 6a52473efb874076a39c4ea21209648e624cf1b4

Published on
Sep 04, 2023
Research Description
weMail &#8211; Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin [wemail] < 1.14.2 WordPress weMail Plugin <= 1.14.1 is vulnerable to Cross Site Request Forgery (CSRF) No patched version is available. Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress weMail Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.
Affected versions
Min -, max 1.14.2.
Status
vulnerable