MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.78.4 - Unauthenticated Admin Email Flooding via subscribe_to_email_list
- ID
- WPSEC-2026-0461
- Plugin
- MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. (mailoptin)
- Affected
- all versions before 1.2.78.5
- Remediation
- Update to 1.2.78.5 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Weakness
- CWE-770
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. on WPSec AttackSurface
- Fix released
- Published
Description
The MailOptin plugin for WordPress is vulnerable to admin email flooding in all versions up to, and including, 1.2.78.4. The public subscribe_to_email_list action does not check that the submitted opt-in campaign exists and has no rate limiting, and the plugin emails the site administrator an error notification, without any throttling, each time a subscription fails because no email provider or list is set for the campaign. This makes it possible for unauthenticated attackers to send repeated subscription requests naming a non-existent campaign, each of which sends an error email to the site administrator and stores a junk lead record.
References
- https://wpsec.com/vuln/WPSEC-2026-0461/
- https://plugins.svn.wordpress.org/mailoptin/tags/1.2.78.5/
- https://wordpress.org/plugins/mailoptin/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS