Skip to content

CVE-2014-4725

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.8179 (81.8%)
Percentil: 99.2%
EPSS: 2026-05-06

Afecta

mailpoet:mailpoet_newsletters

Descripción técnica

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Publicada: 27/7/2014, 18:55:05
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo