Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin mailoptin allows Stored XSS.This issue affects MailOptin: from n/a through <= 1.2.75.0.
Published: 2025-09-03
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during page generation, a CWE‑79 (Cross‑Site Scripting) weakness, present in the MailOptin plugin developed by properfraction. It permits an attacker to store malicious script code that will execute when the data is rendered in visitors’ browsers. This stored cross‑site scripting can enable session hijacking, cookie theft, defacement of content, or the injection of additional harmful payloads within the WordPress environment. Any user who views a page that displays the stored, unsanitized data may have the script executed locally, exposing the site’s integrity and user confidentiality to the attacker.

Affected Systems

The affected product is the MailOptin plugin for WordPress, provided by the vendor properfraction. All installations running version 1.2.75.0 or earlier are vulnerable. The flaw resides in the handling of user‑supplied content such as opt‑in forms or email templates, which are persisted in the database and later inserted into generated pages.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity, while the EPSS score of less than 1 % denotes a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply malicious input that the plugin will store; the likely attack vector is an authenticated site administrator or user with permissions to create or edit opt‑in campaigns. Once the input is stored, any visitor to the affected page will have the script executed in their browser, providing the attacker with potential access to session data or the capability to modify website content. The use of stored XSS elevates the risk compared to reflected XSS because the payload persists and can affect many users over time.

Generated by OpenCVE AI on April 30, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MailOptin plugin to a version newer than 1.2.75.0 where the stored XSS issue has been fixed.
  • Restrict administrative access to the MailOptin configuration and opt‑in management pages to trusted users only.
  • Implement server‑side output escaping or content sanitization for any user‑provided data displayed by the plugin, ensuring that script tags and event handlers are stripped or properly escaped.

Generated by OpenCVE AI on April 30, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26570 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin mailoptin allows Stored XSS.This issue affects MailOptin: from n/a through <= 1.2.75.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 03 Sep 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mailoptin
Mailoptin mailoptin
Wordpress
Wordpress wordpress
Vendors & Products Mailoptin
Mailoptin mailoptin
Wordpress
Wordpress wordpress

Wed, 03 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.
Title WordPress MailOptin Plugin <= 1.2.75.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Mailoptin Mailoptin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:09:29.285Z

Reserved: 2025-09-03T09:02:27.116Z

Link: CVE-2025-58596

cve-icon Vulnrichment

Updated: 2025-09-03T17:39:18.139Z

cve-icon NVD

Status : Deferred

Published: 2025-09-03T15:15:40.290

Modified: 2026-04-23T15:33:25.810

Link: CVE-2025-58596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:30:16Z

Weaknesses