All 3 CVE vulnerabilities found in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce, with AI-generated Chinese analysis, references, and POCs.
Vendor: Sender
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59537 | WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection vulnerability CWE-89 | 7.6 | High | 2026-07-27 |
| CVE-2024-39657 | WordPress Sender plugin <= 2.6.18 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2024-08-26 |
| CVE-2024-43126 | WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.6.14 - Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2024-08-12 |
All 3 known CVE vulnerabilities affecting Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce with full Chinese analysis, references, and POCs where available.