CVE-2014-4725

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.


We have discovered 201 live websites that are affected by CVE-2014-4725.

Test my site




Affected Software

Product  MailPoet Newsletters
Category Wordpress Plugins
Vulnerable Domains201 live websites (1.18% of MailPoet Newsletters install base)
Vulnerable Versions
  • from 0 before 2.6.7
Vulnerable Versions Count42 versions ( 46.15% of all versions)



Details

  • Published - Jul 28, 2014
  • Updated - Aug 6, 2024

CVE-2014-4725 usage by Country

United States60 websites



France24 websites
Germany21 websites
Italy10 websites
Spain9 websites
Poland8 websites
Netherlands6 websites
Brazil5 websites
Australia4 websites
Hungary4 websites

CVE-2014-4725 usage by TLD

.com68 websites
.fr16 websites
.org14 websites
.de11 websites
.it7 websites
.pl7 websites
.nl6 websites
.com.br6 websites
.net4 websites
.com.au4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2014-4725

Top websites that are affected by CVE-2014-4725. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.de Germany***,***
**************.it Italy*,***,***
*************.com Spain*,***,***
************.fr France*,***,***
****.hu Hungary*,***,***
*************.com Bulgaria*,***,***
********.***.au Australia*,***,***
***********.org Germany*,***,***
********.org United States*,***,***
***.******.***.br Brazil*,***,***
See full domain list

FAQ

A total of 201 websites have been identified as vulnerable to CVE-2014-4725, discovered through global website indexing conducted by WebTechSurvey.
MailPoet Newsletters is susceptible to CVE-2014-4725 vulnerability.
MailPoet Newsletters versions before 2.6.7 are vulnerable to CVE-2014-4725.
Version 2.6.7 of MailPoet Newsletters addresses the CVE-2014-4725 security vulnerability.