Executive brief
The EnvíaloSimple plugin for WordPress, which is used for managing email marketing and newsletters, contains a security flaw that could allow an administrator to access sensitive information from the website's database. By sending specially crafted requests, an authorized user with high-level permissions can bypass standard security checks to run unauthorized database queries. This could lead to the exposure of confidential site data, though it requires the attacker to already have administrative access.
Technical details
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection due to insufficient escaping on the 'orderby' user-supplied parameter and a lack of sufficient preparation on existing SQL queries. The vulnerability exists in versions up to and including 2.4.5. An attacker with administrator-level privileges can exploit this via the network by appending malicious SQL statements to legitimate queries. Because the injection is time-based and blind, the attacker can infer data from the database based on the time it takes for the server to respond. This can be used to extract sensitive information such as user credentials or configuration details.
Affected products
- EnvíaloSimple EnvíaloSimple: Email Marketing y Newsletters Up to, and including, 2.4.5
Timeline
- 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/tags/2.4.5/api/contactform7.php
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/tags/2.4.5/api/contactform7.php
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/tags/2.4.5/api/index.php
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/trunk/api/contactform7.php
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/trunk/api/contactform7.php
- https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/trunk/api/index.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a7aa2246-aee9-4992-b030-97e78e3b7d22?source=cve