Pressified develops the SendPress email marketing and newsletter platform, a modestly represented but prominent product in the web application and marketing-automation space. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through web-application weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and missing authorization that are characteristic of server-side form and data-handling code. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pressified over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35040CRITICAL Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6. | Jun 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-41730HIGH Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. | Oct 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2015-9448HIGH The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter. | Sep 26, 2019 | 8.8 | 22 | NO | NO |
CVE-2024-1588MEDIUM The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stor | Apr 8, 2024 | 6.8 | 20 | NO | NO |
CVE-2024-1589MEDIUM The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stor | Apr 8, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47517MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions. | Nov 14, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-5660MEDIUM The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to ins | Nov 7, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-41729MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. | Oct 2, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pressified.
Media articles that mention a CVE ID that affects a product developed by Pressified — matched by CVE ID, not by vendor name.