Mailpoet is a WordPress-focused newsletter and email marketing plugin with a concentrated product portfolio, where reported vulnerabilities center on its core Newsletters offering and reflect authentication and request-handling weaknesses. The durable signal involves CSRF and improper authentication patterns typical of WordPress plugin integrations, alongside cases where vulnerability details remain incomplete; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mailpoet over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4725HIGH The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a craft | Jul 27, 2014 | 7.5 | 75 | NO | YES |
CVE-2014-4726HIGH Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors. | Jul 27, 2014 | 7.5 | 19 | NO | NO |
CVE-2018-20853MEDIUM An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks. | Nov 6, 2019 | 5.3 | 18 | NO | NO |
CVE-2014-3907MEDIUM Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentica | Aug 26, 2014 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mailpoet.
Media articles that mention a CVE ID that affects a product developed by Mailpoet — matched by CVE ID, not by vendor name.