{
 "id": "WPSEC-2026-0499",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0499/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0499/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0499/index.md",
 "title": "MailPoet – Newsletters, Email Marketing, and Automation <= 5.40.0 - Unauthenticated Authentication Bypass via Brute-Forceable Subscriber Link Tokens",
 "description": "The MailPoet plugin for WordPress is vulnerable to Authentication Bypass via subscriber link tokens in all versions up to, and including, 5.40.0. This is due to subscribers that are not given a random token when created, such as those added by the WordPress Users and WooCommerce Customers list synchronization, receiving a token of only six hexadecimal characters derived from the site's AUTH_KEY and the subscriber's email address, leaving roughly 16.7 million possible values. This makes it possible for unauthenticated attackers who know such a subscriber's email address to brute-force the token against the public subscription pages and then view and change that subscriber's subscription details and list memberships, unsubscribe them, or confirm a pending subscription on their behalf.",
 "plugin": {
  "slug": "mailpoet",
  "name": "MailPoet – Newsletters, Email Marketing, and Automation",
  "full_name": "MailPoet – Newsletters, Email Marketing, and Automation",
  "wordpress_org": "https://wordpress.org/plugins/mailpoet/",
  "advisories_url": "https://wpsec.com/vuln/plugin/mailpoet/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/mailpoet"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-330"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.8,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.41.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.41.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.41.0",
 "remediation": "Update to 5.41.0 or later.",
 "fix_released": "2026-10-06T10:35:00+00:00",
 "published": "2026-10-07T10:52:45+00:00",
 "updated": "2026-10-06T14:18:49.760131+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0499/",
  "https://plugins.svn.wordpress.org/mailpoet/tags/5.41.0/",
  "https://wordpress.org/plugins/mailpoet/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/mailpoet",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}