Description
WordPress Plugin MailPress is prone to multiple vulnerabilities, including local file inclusion and security bypass vulnerabilities. Exploiting these issues could allow an attacker to obtain sensitive information that could aid in further attacks or to perform otherwise restricted actions and subsequently add or remove capabilities to WordPress roles. WordPress Plugin MailPress version 5.4.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.6.01)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.9)
WordPress Plugin Contact Form 7 Arbitrary File Upload (3.5.3)
WordPress Plugin User Role by BestWebSoft Cross-Site Scripting (1.5.1)
WordPress Plugin Contact Form Manager Multiple Vulnerabilities (1.4.4)