These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.Referenceshttps://www.exploit-db.com/exploits/45434/https://wordpress.org/plugins/bft-autoresponder/http://www.vapidlabs.com/advisory.php?v=203