CVE-2024-39657: Sender

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.

Affected products

  • Sender Sender: before 2.6.19 (fixed in 2.6.19)

Published 2024-08-26. Last modified 2026-06-17.