S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-10956 Scanner

Targets count_of_send.php and csvexport.php endpoints with insufficient input validation, allowing attackers to read arbitrary local files on the server.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-10956
7.5
CVSS

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Mail Masta plugin for WordPress is an email marketing solution designed to help users manage email campaigns, create lists, design templates, and automate sending. It is widely used by website owners for its ease of use and cost-effectiveness, making it a popular choice among WordPress users seeking efficient email marketing tools.

CVE-2016-10956 is a Local File Inclusion (LFI) vulnerability that arises from insufficient input validation in the plugin. Attackers can manipulate file path parameters to include arbitrary local files, bypassing intended access controls. This flaw exists because the plugin fails to sanitize user-supplied input before using it in file inclusion functions.

Specifically, the vulnerability is present in the count_of_send.php and csvexport.php files. The vulnerable parameters allow attackers to specify file paths without proper validation, enabling them to include sensitive files like /etc/passwd or wp-config.php. This can be exploited remotely without authentication, making it a critical security issue.

If exploited, an attacker can read sensitive data such as database credentials, server logs, and user information. This could lead to full site compromise, data theft, or further attacks like privilege escalation. The CVSS score of 7.5 highlights the high severity and potential for significant damage to affected WordPress sites.

Solution Advice
  • Update the Mail Masta plugin to the latest patched version immediately.
  • Implement strict input validation and sanitization for all file path parameters.
  • Disable or remove the vulnerable count_of_send.php and csvexport.php files if not needed.
  • Use a web application firewall (WAF) to block malicious file inclusion attempts.
  • Regularly audit and update all WordPress plugins and themes.
  • Restrict file permissions to prevent unauthorized access to sensitive files.
  • Monitor server logs for unusual file access patterns or inclusion attempts.
  • Conduct periodic vulnerability scans using tools like S4E to detect similar issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Mail Masta LFI Scanner | S4E Free Check