Vulnerabilities (CVE)

Filtered by vendor Postieplugin Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-20203 1 Postieplugin 1 Postie 2020-08-24 5.0 MEDIUM 5.3 MEDIUM
The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.
CVE-2019-20204 1 Postieplugin 1 Postie 2020-01-16 3.5 LOW 5.4 MEDIUM
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.