Input validation vulnerability in Email Artillery (MASS EMAIL) 4.1

The Email Artillery plugin for WordPress is vulnerable to malicious activity in versions up to and including 4.1. Attackers can exploit the plugin by using the ‘cpage’ and ‘site_id’ parameters, which don’t properly filter input or escape output. If a user clicks on a link, the attacker can inject web scripts into the page. This puts the user at risk of having their data stolen or manipulated. It is important to update the plugin to a secure version to protect yourself from these kinds of attacks.

Detected in:

Email Artillery (MASS EMAIL) open vulnerable versions: >= * <= 4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.