← WordPress Vulnerabilities
WordPress security by component

MailPoet

MailPoet is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: mailpoet

CVE-2026-57626: MailPoet: Cross-site request forgery

MailPoet is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is 5.30.0 through 5.33.0.

PublishedJul 23, 2026
Known safe version5.33.1
Safe version
Jul 23, 2026 CVE-2026-57626
MailPoet: Cross-site request forgery
MailPoet is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is 5.30.0 through 5.33.0.
5.33.1
CVE7.1
NVDPending
May 15, 2025 CVE-2024-12743
MailPoet: Cross-site scripting
MailPoet is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Nov 19, 2024 CVE-2024-10103
process of testing the MailPoet: Cross-site scripting
process of testing the MailPoet is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 02, 2020 CVE-2019-11843
Mailpoet: Cross-site scripting
Mailpoet is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1