Executive brief
Mailster is a popular email marketing plugin for WordPress used to manage newsletters and campaigns. A security flaw allows users with 'Editor' level permissions to upload malicious files to the web server. If exploited, an attacker could gain full control over the website, leading to data theft, site defacement, or the installation of persistent backdoors.
Technical details
The Mailster plugin for WordPress (versions 4.1.17 and below) contains an unrestricted file upload vulnerability (CWE-434) within its editor functionality. While the attack requires 'Editor' level privileges (PR:H), the lack of proper file type validation allows an authenticated user to upload executable scripts (such as PHP shells) to the server. Successful exploitation results in a scope change (S:C), granting the attacker full remote code execution (RCE) capabilities over the underlying web environment. The issue is resolved in version 4.1.18.
Affected products
- EverPress Mailster <= 4.1.17
Timeline
- 2025-12-12: other: Reported by researcher Phat RiO
- 2026-07-22: patched: Patch released in version 4.1.18
- 2026-07-23: disclosed: NVD publication date