Input validation vulnerability in EnvíaloSimple: Email Marketing y Newsletters 2.1

The EnvíaloSimple: Email Marketing and Newsletters plugin for WordPress is vulnerable to a type of cyber attack called a PHP Object Injection. All versions of the plugin up to and including version 2.1 are affected. This type of attack makes it possible for unauthenticated attackers to inject a malicious code into the vulnerable plugin. This code could allow the attacker to delete files, steal data, or run malicious code on the target system. If another plugin or theme is installed on the target system, it could also give the attacker the ability to exploit more vulnerabilities.

Detected in:

EnvíaloSimple: Email Marketing y Newsletters open vulnerable versions: >= * <= 2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.