MailPoet – Newsletters, Email Marketing, and Automation 5.30.0-5.33.0 - Cross-Site Request Forgery
medium
The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 5.30.0-5.33.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a f...
- CVSS:
- 4.3
- Affected:
- 5.30.0 – 5.33.0
- Fixed in:
- 5.33.1
- Disclosed:
- Jul 21, 2026
CVE-2026-57626 on NVD →
MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.5.2
unknown
[en] The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.5.2
- Fixed in:
- 5.5.2
- Disclosed:
- May 15, 2025
CVE-2024-12743 on NVD →
MailPoet <= 5.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.2
- Disclosed:
- Mar 6, 2025
CVE-2024-12743 on NVD →
MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.3.2
unknown
[en] In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Nov 19, 2024
CVE-2024-10103 on NVD →
MailPoet <= 5.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.2
- Disclosed:
- Oct 29, 2024
CVE-2024-10103 on NVD →
MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 3.23.2
unknown
[en] The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
- Affected:
- up to 3.23.2
- Fixed in:
- 3.23.2
- Disclosed:
- Jun 2, 2020
CVE-2019-11843 on NVD →
MailPoet – emails and newsletters in WordPress <= 3.23.1 - Reflected Cross-Site Scripting via URL parameter
medium
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
- CVSS:
- 6.1
- Affected:
- up to 3.23.2
- Fixed in:
- 3.23.2
- Disclosed:
- Apr 16, 2019
CVE-2019-11843 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database