Input validation vulnerability in ALO EasyMail Newsletter 2.7.0

The ALO EasyMail Newsletter plugin for WordPress is not secure in versions up to, and including, 2.6.01. If someone who is not authenticated (not logged in) can trick a site administrator into clicking a link, they can insert malicious code that could cause harm. To protect against this, the plugin needs to be updated to have better validation of nonce.

Detected in:

ALO EasyMail Newsletter open vulnerable versions: >= * < 2.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.