← Back

Customize Wordpress Emails And Alerts

customize_wordpress_emails_and_alerts

Vendor: Madewithfuel • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Madewithfuel
1Customize Wordpress Emails And Alerts
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-ma...Show more
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).Show less