# MailPoet – Newsletters, Email Marketing, and Automation <= 5.40.0 - Unauthenticated Authentication Bypass via Brute-Forceable Subscriber Link Tokens

- **ID:** WPSEC-2026-0499
- **Plugin:** MailPoet – Newsletters, Email Marketing, and Automation (`mailpoet`), https://wordpress.org/plugins/mailpoet/
- **Affected versions:** all versions before 5.41.0
- **Fixed in:** 5.41.0 (Update to 5.41.0 or later.)
- **Severity:** Medium 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-330
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/mailpoet
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0499/

## Description

The MailPoet plugin for WordPress is vulnerable to Authentication Bypass via subscriber link tokens in all versions up to, and including, 5.40.0. This is due to subscribers that are not given a random token when created, such as those added by the WordPress Users and WooCommerce Customers list synchronization, receiving a token of only six hexadecimal characters derived from the site's AUTH_KEY and the subscriber's email address, leaving roughly 16.7 million possible values. This makes it possible for unauthenticated attackers who know such a subscriber's email address to brute-force the token against the public subscription pages and then view and change that subscriber's subscription details and list memberships, unsubscribe them, or confirm a pending subscription on their behalf.

## References

- https://wpsec.com/vuln/WPSEC-2026-0499/
- https://plugins.svn.wordpress.org/mailpoet/tags/5.41.0/
- https://wordpress.org/plugins/mailpoet/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0499/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
