Optinmonster is a WordPress-based lead-capture and conversion-optimization plugin with a modestly broad user base, and its disclosed vulnerabilities center on web application input handling and access control. The recurring weakness classes include cross-site scripting, authorization bypass, cleartext transmission of sensitive data, and related flaws endemic to form-handling and user-session logic in web plugins. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Optinmonster over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39341HIGH The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_ | Nov 1, 2021 | 8.2 | 50 | NO | YES |
CVE-2021-39325MEDIUM The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php | Sep 20, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-0772MEDIUM The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticat | Mar 13, 2023 | 6.5 | 20 | NO | NO |
CVE-2016-10996MEDIUM The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak. | Sep 20, 2019 | 5.3 | 19 | NO | NO |
CVE-2024-4045MEDIUM The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ca | May 25, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Optinmonster.
Media articles that mention a CVE ID that affects a product developed by Optinmonster — matched by CVE ID, not by vendor name.