Input validation vulnerability in SendPress Newsletters 1.22.3.31

The SendPress Newsletters plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery (CSRF). This means that if an unauthenticated attacker can trick a site administrator into clicking on a link or taking some other action, it may be possible for the attacker to perform an unauthorized action. This vulnerability affects versions of the plugin up to and including 1.22.3.31 and is caused by missing nonce validation on an unknown function.

Detected in:

SendPress Newsletters open vulnerable versions: >= * <= 1.23.11.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.