Cross-Site Request Forgery Vulnerability in MailPoet Plugin by WordPress
CVE-2026-57626

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-57626?

The MailPoet plugin for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability that can allow attackers to perform unauthorized actions on behalf of authenticated users. This vulnerability affects versions 5.30.0 through 5.33.0, potentially compromising the security of users' data and providing a gateway for malicious activities. Maintenance of secure communications and prompt application of updates can mitigate the risks associated with this issue.

Affected Version(s)

MailPoet 5.30.0 <= 5.33.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.