← Back

CVE-2014-4725

nvd nist
Published: Jul 27, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Affected (69)

1 product
Mailpoet Newsletters
Configuration A
69 vulnerable
Vulnerable SoftwareAffected Versions
Mailpoet
Up to 2.6.6
Version 0.9.1
Version 0.9.2
Version 0.9.6
Version 0.9
Version 1.0.1
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9.5
Version 2.0.9
Version 2.0
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1.8
Version 2.1.9
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.7
Version 2.5.8
Version 2.5.9.1
Version 2.5.9.2
Version 2.5.9.3
Version 2.5.9.4
Version 2.5.9
Version 2.5
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6
Version 2.6 beta

Timeline

No history available yet.