plugin

Mailoptin Vulnerabilities

13 known security issues reported for the Mailoptin WordPress plugin. Most recent disclosed Jul 29, 2026.

1 critical 1 high 5 medium

Running Mailoptin on your site? Check whether your installed version is affected.

Scan your site free

MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.78.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.78.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...

CVSS:
6.4
Affected:
up to 1.2.78.0
Fixed in:
1.2.78.1
Disclosed:
Jul 29, 2026

CVE-2026-66703 on NVD →

MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.77.3 - Unauthenticated Privilege Escalation

critical

The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.77.3. This makes it possible for unauthenticated attackers to elevate their privileges.

CVSS:
9.8
Affected:
up to 1.2.77.3
Fixed in:
1.2.78.0
Disclosed:
Jul 9, 2026

CVE-2026-57813 on NVD →

MailOptin <= 1.2.75.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.75.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 1.2.75.0
Fixed in:
1.2.75.1
Disclosed:
Sep 3, 2025

CVE-2025-58596 on NVD →

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.75.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.

Affected:
up to 1.2.75.1
Fixed in:
1.2.75.1
Disclosed:
Sep 3, 2025

CVE-2025-58596 on NVD →

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.70.4 (closed)

unknown

[en] The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied at...

Affected:
up to 1.2.70.4
Fixed in:
1.2.70.4
Disclosed:
Sep 24, 2024

CVE-2024-8628 on NVD →

Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied attribu...

CVSS:
5.4
Affected:
up to 1.2.70.3
Fixed in:
1.2.70.4
Disclosed:
Sep 23, 2024

CVE-2024-8628 on NVD →

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.54.1 (closed)

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions.

Affected:
up to 1.2.54.1
Fixed in:
1.2.54.1
Disclosed:
Apr 6, 2023

CVE-2023-23980 on NVD →

MailOptin <= 1.2.54.0 - Authenticated (Admin+) Cross Site Scripting

medium

The MailOptin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.54.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin-level permissions and above, to inject arbitrary web scripts in pages that will e...

CVSS:
5.5
Affected:
1.2.54.0 – 1.2.54.0
Fixed in:
1.2.54.1
Disclosed:
Jan 20, 2023

CVE-2023-23980 on NVD →

MailOptin <= 1.2.49.0 - Missing Authorization to Cache Deletion

medium

The MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the clear_optin_cache function in versions up to, and including, 1.2.49.0. This makes it possible for unauthenticated attackers to clear the plugin's cache. Additionally, the function was also missing a nonce c...

CVSS:
5.3
Affected:
up to 1.2.49.0
Fixed in:
1.2.50.0
Disclosed:
Sep 23, 2022

CVE-2022-36340 on NVD →

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.50.0 (closed)

unknown

[en] Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.

Affected:
up to 1.2.50.0
Fixed in:
1.2.50.0
Disclosed:
Sep 23, 2022

CVE-2022-36340 on NVD →

Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.35.1 - Authorization Bypass

high

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the fetch_custom_fields and fetch_tags functions in versions up to, and including, 1.2.35.1. This makes it possible for unauthenticated att...

CVSS:
7.3
Affected:
up to 1.2.35.1
Fixed in:
1.2.35.2
Disclosed:
Jun 30, 2021

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.35.2 (closed)

unknown

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the fetch_custom_fields and fetch_tags functions in versions up to, and including, 1.2.35.1. This makes it possible for unauthenticated att...

Affected:
up to 1.2.35.2
Fixed in:
1.2.35.2
Disclosed:
Jun 30, 2021

Popup, Optin Form &amp; Email Newsletters for Mailchimp, HubSpot, AWeber &#8211; MailOptin [mailoptin] < 1.2.35.2 (closed)

unknown

The fetch_custom_fields and fetch_tags function did not have proper CSRF check and authorisation, allowing unauthorised users to call the related AJAX action via either low privilege account or CSRF attack

Affected:
up to 1.2.35.2
Fixed in:
1.2.35.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database