MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.78.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.78.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...
- CVSS:
- 6.4
- Affected:
- up to 1.2.78.0
- Fixed in:
- 1.2.78.1
- Disclosed:
- Jul 29, 2026
CVE-2026-66703 on NVD →
MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.77.3 - Unauthenticated Privilege Escalation
critical
The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.77.3. This makes it possible for unauthenticated attackers to elevate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 1.2.77.3
- Fixed in:
- 1.2.78.0
- Disclosed:
- Jul 9, 2026
CVE-2026-57813 on NVD →
MailOptin <= 1.2.75.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.75.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 4.4
- Affected:
- up to 1.2.75.0
- Fixed in:
- 1.2.75.1
- Disclosed:
- Sep 3, 2025
CVE-2025-58596 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.75.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.
- Affected:
- up to 1.2.75.1
- Fixed in:
- 1.2.75.1
- Disclosed:
- Sep 3, 2025
CVE-2025-58596 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.70.4 (closed)
unknown
[en] The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied at...
- Affected:
- up to 1.2.70.4
- Fixed in:
- 1.2.70.4
- Disclosed:
- Sep 24, 2024
CVE-2024-8628 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied attribu...
- CVSS:
- 5.4
- Affected:
- up to 1.2.70.3
- Fixed in:
- 1.2.70.4
- Disclosed:
- Sep 23, 2024
CVE-2024-8628 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.54.1 (closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions.
- Affected:
- up to 1.2.54.1
- Fixed in:
- 1.2.54.1
- Disclosed:
- Apr 6, 2023
CVE-2023-23980 on NVD →
MailOptin <= 1.2.54.0 - Authenticated (Admin+) Cross Site Scripting
medium
The MailOptin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.54.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin-level permissions and above, to inject arbitrary web scripts in pages that will e...
- CVSS:
- 5.5
- Affected:
- 1.2.54.0 – 1.2.54.0
- Fixed in:
- 1.2.54.1
- Disclosed:
- Jan 20, 2023
CVE-2023-23980 on NVD →
MailOptin <= 1.2.49.0 - Missing Authorization to Cache Deletion
medium
The MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_optin_cache function in versions up to, and including, 1.2.49.0. This makes it possible for unauthenticated attackers to clear the plugin's cache. Additionally, the function was also missing a nonce c...
- CVSS:
- 5.3
- Affected:
- up to 1.2.49.0
- Fixed in:
- 1.2.50.0
- Disclosed:
- Sep 23, 2022
CVE-2022-36340 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.50.0 (closed)
unknown
[en] Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
- Affected:
- up to 1.2.50.0
- Fixed in:
- 1.2.50.0
- Disclosed:
- Sep 23, 2022
CVE-2022-36340 on NVD →
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.35.1 - Authorization Bypass
high
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the fetch_custom_fields and fetch_tags functions in versions up to, and including, 1.2.35.1. This makes it possible for unauthenticated att...
- CVSS:
- 7.3
- Affected:
- up to 1.2.35.1
- Fixed in:
- 1.2.35.2
- Disclosed:
- Jun 30, 2021
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.35.2 (closed)
unknown
The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the fetch_custom_fields and fetch_tags functions in versions up to, and including, 1.2.35.1. This makes it possible for unauthenticated att...
- Affected:
- up to 1.2.35.2
- Fixed in:
- 1.2.35.2
- Disclosed:
- Jun 30, 2021
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin [mailoptin] < 1.2.35.2 (closed)
unknown
The fetch_custom_fields and fetch_tags function did not have proper CSRF check and authorisation, allowing unauthorised users to call the related AJAX action via either low privilege account or CSRF attack
- Affected:
- up to 1.2.35.2
- Fixed in:
- 1.2.35.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database