Mailoptin is an email marketing and automation plugin with a focused product footprint centered on web-form capture and subscriber-list management, representing a narrowly scoped attack surface typical of WordPress-ecosystem extensions. The durable signal in its vulnerability profile points to application-layer input-handling and authorization weaknesses, specifically cross-site scripting in form generation and missing authorization checks, which are characteristic of plugins that bridge user input with administrative functions and data access.
The number and severity of CVEs published that impact products developed by Mailoptin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36340MEDIUM Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress. | Sep 23, 2022 | 5.3 | 20 | NO | NO |
CVE-2023-23980MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions. | Apr 6, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-8628MEDIUM The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' | Sep 24, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailoptin.
Media articles that mention a CVE ID that affects a product developed by Mailoptin — matched by CVE ID, not by vendor name.