The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
We have discovered 201 live websites that are affected by CVE-2014-4725.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 201 live websites (1.18% of MailPoet Newsletters install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 42 versions ( 46.15% of all versions) |
![]() | 60 websites |
![]() | 24 websites |
![]() | 21 websites |
![]() | 10 websites |
![]() | 9 websites |
![]() | 8 websites |
![]() | 6 websites |
![]() | 5 websites |
![]() | 4 websites |
![]() | 4 websites |
.com | 68 websites |
.fr | 16 websites |
.org | 14 websites |
.de | 11 websites |
.it | 7 websites |
.pl | 7 websites |
.nl | 6 websites |
.com.br | 6 websites |
.net | 4 websites |
.com.au | 4 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.de | ![]() | ***,*** | |
**************.it | ![]() | *,***,*** | |
*************.com | ![]() | *,***,*** | |
************.fr | ![]() | *,***,*** | |
****.hu | ![]() | *,***,*** | |
*************.com | ![]() | *,***,*** | |
********.***.au | ![]() | *,***,*** | |
***********.org | ![]() | *,***,*** | |
********.org | ![]() | *,***,*** | |
***.******.***.br | ![]() | *,***,*** |
FAQ