PLUGIN SECURITY
Is Optinmonster safe?
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
What this plugin does
- Slug:
optinmonster - Author: Syed Balkhi
- 1000000+ active installs
- 86/100 rating (815 reviews on wordpress.org)
- 134135779 all-time downloads
- On WordPress.org since 2015-04-26
ecommercemarketingOptinpopuppopups
Maintenance status
- Latest known version: 2.16.24
- Last updated: 2026-08-14 1:49pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for Optinmonster. Reported between 2016 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-4045 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.16.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.16.2 | 2.16.2 | 2024-05-24 | ✓ fixed in latest |
| CVE-2024-33691 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.16.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.16.0 | 2.16.0 | 2024-04-26 | ✓ fixed in latest |
| CVE-2023-0772 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.12.2 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 2.12.2 | 2.12.2 | 2023-03-03 | ✓ fixed in latest |
| CVE-2021-39341 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.6.5 | Improper Authorization | High 8.2 | < 2.6.5 | 2.6.5 | 2021-10-27 | ✓ fixed in latest |
| CVE-2021-39325 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.6.1 | 2.6.1 | 2021-09-20 | ✓ fixed in latest |
| CVE-2021-34650 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 2.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.6.5 | 2.6.5 | 2021-09-20 | ✓ fixed in latest |
| — | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 1.1.4.6 | — | Unknown | < 1.1.4.6 | 1.1.4.6 | 2016-03-22 | ✓ fixed in latest |
| CVE-2016-10996 | Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation [optinmonster] < 1.1.4.6 | Incorrect Authorization | Medium 5.3 | < 1.1.4.6 | 1.1.4.6 | 2016-01-14 | ✓ fixed in latest |
How to fix it
Keep Optinmonster updated — 2.16.24 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce — 7000000+ active installs — 90/100 (4820)
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — 700000+ active installs — 98/100 (4503) — max PHP 8.4
- Pinterest for WooCommerce — 300000+ active installs — 46/100 (68) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.