CVE-2024-7384

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

<h4>💌 UNLEASH THE POWER OF EMAIL MARKETING AUTOMATION:</h4> <ul> <li>Effortlessly create attention-grabbing newsletters with our intuitive drag-and-drop editor &#8211; no HTML skills required.</li> <li>Automate your newsletter formation process using pre-saved zones.</li> <li>Seamlessly include your WordPress articles in your newsletters.</li> <li>Personalize your newsletters with user data such as name, email, or custom fields.</li> <li>Implement social media share options for Twitter, Facebook, and LinkedIn to expand your reach.</li> <li>Experience mobile-responsive default templates with previews for desktop and mobile versions.</li> </ul> <h4>📊 TAKE YOUR EMAIL MARKETING TO THE NEXT LEVEL:</h4> <ul> <li>Conduct automated mass actions on users, including sending birthday newsletters, welcome greetings, and more.</li> <li>Plan follow-up newsletter sequences based on user interaction to nurture and engage your audience.</li> <li>Effortlessly schedule your newsletters for timely delivery.</li> <li>Automatically send timely reminders to recover abandoned WooCommerce shopping carts.</li> <li>Create and duplicate marketing automation workflows with ease.</li> <li>Handle bounce emails efficiently for improved deliverability.</li> </ul> <h4>📥 ENHANCE DELIVERABILITY AND ENSURE GDPR COMPLIANCE:</h4> <ul> <li>Effectively dispatch emails in real-time using our queue system.</li> <li>Follow recommendations from our analysis tool to optimize your deliverability.</li> <li>Track reliable statistics to gain insights into your newsletter performance.</li> </ul> <h4>👤 EFFICIENT CONTACT LIST MANAGEMENT WITH GDPR COMPLIANCE:</h4> <ul> <li>Effortlessly manage your subscribers with AcyMailing.</li> <li>Import users seamlessly from any platform or source.</li> <li>Utilize efficient filter options to target specific user segments.</li> <li>Automatically subscribe users during registration for streamlined list management.</li> <li>Handle false email addresses and integrate strong captchas for enhanced data security.</li> </ul> <h4>⤵️ EXPLORING MORE WITH ACYMAILING:</h4> <ul> <li>Enjoy various integrations available: <a href="https://wordpress.org/plugins/acymailing-integration-for-business-directory/" rel="ugc">Business Directory</a>, <a href="https://wordpress.org/plugins/acymailing-integration-for-contact-form-7/" rel="ugc">Contact Form 7</a>, <a href="https://wordpress.org/plugins/acymailing-integration-for-easy-digital-downloads/" rel="ugc">Easy Digital Downloads</a>, <a href="https://wordpress.org/plugins/acymailing-integration-for-gravity-forms/" rel="ugc">Gravity Forms</a>, <a href="https://zapier.com/apps/acymailing/integrations" rel="nofollow ugc">Zapier</a>, <a href="https://www.make.com/en/integrations/acymailing" rel="nofollow ugc">Make.com</a>, <a href="https://wordpress.org/plugins/acymailing-integration-for-woocommerce/" rel="ugc">WooCommerce</a>, <a href="https://wordpress.org/plugins/acymailing-integration-for-the-events-calendar/" rel="ugc">The Events Calendar</a>, etc&#8230;</li> <li>Experience the power of AcyMailing with <a href="https://demo.acymailing.com/?utm_source=wp_org&amp;utm_campaign=test_acymailing&amp;utm_medium=description_link" rel="nofollow ugc">our demo site</a>.</li> <li>Leverage diverse external sending services &#8211; <a href="https://www.acymailing.com/our-own-sending-service/" rel="nofollow ugc">AcyMailing Sending Service</a>, <a href="https://docs.acymailing.com/external-sending-method/sendinblue" rel="nofollow ugc">Brevo/Sendinblue</a>, <a href="https://docs.acymailing.com/external-sending-method/mailgun" rel="nofollow ugc">Mailgun</a>, <a href="https://docs.acymailing.com/external-sending-method/sendgrid" rel="nofollow ugc">SendGrid</a>, <a href="https://docs.acymailing.com/external-sending-method/amazon-ses" rel="nofollow ugc">Amazon SES</a>, SMTP and more.</li> </ul> <p>🔎Stay tuned to know every update on our plugins. Follow us on <a href="https://www.linkedin.com/company/acymailing/" rel="nofollow ugc">LinkedIn</a>, <a href="https://x.com/acymailingoff" rel="nofollow ugc">Twitter</a>, <a href="https://www.facebook.com/AcyMailing/" rel="nofollow ugc">Facebook</a>, or our <a href="https://www.acymailing.com" rel="nofollow ugc">website</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
211K