MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. <= 1.2.78.4 - Unauthenticated Admin Email Flooding via subscribe_to_email_list

Medium 5.3 CWE-770Fixed in 1.2.78.5
ID
WPSEC-2026-0461
Plugin
MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. (mailoptin)
Affected
all versions before 1.2.78.5
Remediation
Update to 1.2.78.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness
CWE-770
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. on WPSec AttackSurface
Fix released
Published

Description

The MailOptin plugin for WordPress is vulnerable to admin email flooding in all versions up to, and including, 1.2.78.4. The public subscribe_to_email_list action does not check that the submitted opt-in campaign exists and has no rate limiting, and the plugin emails the site administrator an error notification, without any throttling, each time a subscription fails because no email provider or list is set for the campaign. This makes it possible for unauthenticated attackers to send repeated subscription requests naming a non-existent campaign, each of which sends an error email to the site administrator and stores a junk lead record.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0