CVE-2021-44779: [gwa] Autoresponder Project [gwa] Autoresponder

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.

Affected products

Published 2022-02-04. Last modified 2026-06-17.