Junglewise Threat Intelligence

CVE-2026-57626: MailPoet Cross-Site Request Forgery in WordPress plugin

CVE-2026-57626 · Severity: high · CVSS 7.1 · Published 2026-07-23

Executive brief

MailPoet is a popular WordPress plugin used for creating and sending email newsletters. A security vulnerability has been identified that could allow an attacker to trick an administrator into performing unintended actions on the website, such as changing settings or deleting content. This occurs if a logged-in administrator visits a malicious link or website while their session is active.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the MailPoet plugin for WordPress (versions 5.30.0 through 5.33.0). The flaw is caused by insufficient validation of request origins, allowing an unauthenticated attacker to craft malicious requests that are executed in the context of a privileged user. To exploit this, an attacker must trick a logged-in administrator or other high-privilege user into interacting with a malicious link or form. Successful exploitation can lead to unauthorized configuration changes or other administrative actions. The issue is resolved in version 5.33.1.

Affected products

  • MailPoet MailPoet 5.30.0 through 5.33.0

Timeline

  • 2026-06-24: disclosed: Reported by Nguyen Ba Khanh
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: patched: Patch availability confirmed in version 5.33.1

References