Skip to main content

Vendor/product archive

wpmailster / wp_mailster CVEs

Beta · best-effort

12 CVEs tagged to wpmailster / wp_mailster0 Critical, 5 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-24598

Published Feb 4, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24559

Published Feb 3, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22303

Published Jan 7, 2025

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54355

Published Dec 16, 2024

Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through <= 1.8.17.0.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53807

Published Dec 6, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster wp-mailster allows Blind SQL Injection.This issue affec…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53805

Published Dec 6, 2024

Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53804

Published Dec 6, 2024

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53803

Published Dec 6, 2024

Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: fr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11782

Published Dec 3, 2024

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53737

Published Nov 28, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Stored XSS.This issue affects WP Mai…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28975

Published Oct 21, 2021

WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17451

Published Dec 7, 2017

The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1