Filtered by vendor Enl Newsletter Plugin Project
Subscriptions
Filtered by product Enl-newsletter
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-3059 | 1 Enl Newsletter Plugin Project | 1 Enl-newsletter | 2024-10-28 | 5.7 Medium |
The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack | ||||
CVE-2014-4939 | 1 Enl Newsletter Plugin Project | 1 Enl-newsletter | 2024-09-17 | N/A |
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php. |
Page 1 of 1.