Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-4725

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.385
EPSS Ranking 97.1%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2014-4725


Contact Us

Shodan ® - All rights reserved