PLUGIN SECURITY
Is Mailpoet safe?
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
What this plugin does
- Slug:
mailpoet - Author: MailPoet
- 500000+ active installs
- 88/100 rating (1431 reviews on wordpress.org)
- 68813102 all-time downloads
- On WordPress.org since 2016-10-28
email automationEmail Marketingnewsletterpost notificationwoocommerce emails
Maintenance status
- Latest known version: 5.35.0
- Last updated: 2026-08-25 4:51am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
Known vulnerabilities
4 known CVEs on file for Mailpoet.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-12743 | MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.5.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 5.5.2 | 5.5.2 | 2025-03-06 | ✓ fixed in latest |
| CVE-2024-10103 | MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.3.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 5.3.2 | 5.3.2 | 2024-10-29 | ✓ fixed in latest |
| CVE-2019-11843 | MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 3.23.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.23.2 | 3.23.2 | 2019-04-16 | ✓ fixed in latest |
| — | MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.33.1 | — | Unknown | < 5.33.1 | 5.33.1 | 0000-00-00 | ✓ fixed in latest |
| — | MailPoet < 5.14.2 - Reflected XSS | — | Unknown | < 5.14.2 | 5.14.2 | — | ✓ fixed in latest |
| — | MailPoet < 5.22.4 - Authenticated SQLi via sort_by | — | Unknown | < 5.22.4 | 5.22.4 | — | ✓ fixed in latest |
| CVE-2026-57626 | MailPoet < 5.33.1 - Cross-Site Request Forgery | — | Unknown | < 5.33.1 | 5.33.1 | — | ✓ fixed in latest |
How to fix it
Keep Mailpoet updated — 5.35.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- Newsletter – Send awesome emails from WordPress — 200000+ active installs — 92/100 (1203) — max PHP 8.4
- Brevo – Email, SMS, Web Push, Chat, and more. — 100000+ active installs — 82/100 (285) — max PHP 8.4
- Newsletters, Email Marketing, SMS and Popups by Omnisend — 100000+ active installs — 96/100 (16) — max PHP 8.4
- FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution — 80000+ active installs — 96/100 (249) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.