Impact
This vulnerability, identified as a Contributor XSS, exists in WordPress MailOptin plugin versions up to 1.2.78.0. It permits a malicious user to inject JavaScript into the plugin’s web pages, potentially defacing the site, hijacking user sessions, or launching further attacks. The weakness is classified as CWE-79, reflecting unsanitized input handling.
Affected Systems
Affected are WordPress sites running the MailOptin plugin version 1.2.78.0 or earlier, provided by the vendor properfraction.
Risk and Exploitability
With a CVSS score of 6.5 the risk is moderate. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the web interface, where a privileged or even unauthenticated user could supply input that is rendered without proper escaping. Because XSS does not require authentication and can be triggered via normal plugin usage, exploitation chances are non‑negligible but have not yet been observed publicly.
OpenCVE Enrichment