VendorsAutomatticmailpoetall versions
Vulnerabilities

Automattic MailPoet

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-11843
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
Published 2020-06-02 · Modified
6.1EPSS 0.018
CVE-2024-10103
MailPoet < 5.3.2 - Admin+ Stored XSS
Published 2024-11-19 · Analyzed
6.1EPSS 0.003
CVE-2024-12743
MailPoet < 5.5.2 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003