Skip to main content

Vendor/product archive

automattic / mailpoet CVEs

Beta · best-effort

3 CVEs tagged to automattic / mailpoet0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-12743

Published May 15, 2025

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Sc…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10103

Published Nov 19, 2024

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malic…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11843

Published Jun 2, 2020

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1