Executive brief
MailOptin is a popular WordPress plugin used for lead generation, email marketing, and creating popups. A critical security flaw allows an attacker to gain unauthorized administrative access to the website. This could lead to a complete site takeover, theft of customer data, or the distribution of malicious content to site visitors.
Technical details
The MailOptin plugin for WordPress (versions up to and including 1.2.77.3) contains an incorrect privilege assignment vulnerability (CWE-266). The flaw allows an unauthenticated remote attacker to escalate their privileges to a higher level, such as an administrator, without any user interaction. This is achieved by exploiting a failure in the plugin's logic for assigning or verifying user roles. Successful exploitation grants the attacker full control over the WordPress environment. The issue is resolved in version 1.2.78.0.
Affected products
- properfraction MailOptin <= 1.2.77.3
Timeline
- 2026-06-15: other: Vulnerability reported by researcher qdtad
- 2026-07-09: advisory: Patchstack published initial advisory
- 2026-07-13: disclosed: CVE published to NVD dataset
- 2026-07-13: patched: Patch confirmed available in version 1.2.78.0