← back to popular plugins
wordfence / plugin · kadence-woocommerce-email-designer

Kadence WooCommerce Email Designer

kadence-woocommerce-email-designer
total installs
100,000
total vulns
3
critical
0
high
3
medium
0
low
0
latest vuln
patched
3
unpatched
0
avg time to patch
vulnerabilities (3)
Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scripting
high ✓ patched
cvss score 7.2
cwe CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published Dec 1, 2025
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Kadence WooCommerce Email Designer <= 1.5.16 - Authenticated (Shop Manager+) Arbitrary Options Update
high ✓ patched
cvss score 7.2
cwe CWE-20: Improper Input Validation
published Aug 14, 2025
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to insufficient input validation on the import_woomail() function in all versions up to, and including, 1.5.16. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Kadence WooCommerce Email Designer <= 1.5.14 - Authenticated (Admin+) Arbitrary File Upload
high ✓ patched
cvss score 7.2
cwe CWE-434: Unrestricted Upload of File with Dangerous Type
published Apr 16, 2025
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.5.14. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.