Wpmailster is a WordPress plugin focused on email marketing and newsletter distribution, a modestly represented but well-positioned component in the WordPress ecosystem. Its vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability; the exposure concentrates in cross-site scripting, sensitive data disclosure, authorization bypass, and CSRF flaws that are characteristic of web-facing administrative plugins. Defenders should treat this vendor's advisories as a patching priority for affected WordPress installations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmailster over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17451MEDIUM The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php. | Dec 7, 2017 | 6.1 | 32 | NO | YES |
CVE-2024-53807CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster wp-mailster allows Blind SQL Injection.This issue affect | Dec 6, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-53805CRITICAL Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: fro | Dec 6, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-54355HIGH Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through <= 1.8.17.0. | Dec 16, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-53803HIGH Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: fro | Dec 6, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-22303HIGH Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/ | Jan 7, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-53804HIGH Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/ | Dec 6, 2024 | 7.5 | 21 | NO | NO |
CVE-2021-28975MEDIUM WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter. | Oct 21, 2021 | 6.1 | 20 | NO | NO |
CVE-2025-24598MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP M | Feb 4, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-24559MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Reflected XSS.This issue affects WP M | Feb 3, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmailster.
Media articles that mention a CVE ID that affects a product developed by Wpmailster — matched by CVE ID, not by vendor name.