CVE-2015-9409: Alo-Easymail Project Alo-Easymail
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
Affected products
- Alo-Easymail Project Alo-Easymail: before 2.6.01 (fixed in 2.6.01)
Published 2019-09-25. Last modified 2026-06-17.