EO4WP: EmailOctopus for WordPress
EO4WP: EmailOctopus for WordPress has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for EO4WP: EmailOctopus for WordPress has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. EO4WP: EmailOctopus for WordPress is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-30763EO4WP <= 1.0.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

EO4WP: EmailOctopus for WordPress
Author
Olaf Lederer
Email marketing is still one of the best ways to drive traffic to your website. Use this plugin to add EmailOctopus subscription forms directly with the WordPress Block Editor or Elementor Pro. A shortcode is available for advanced and custom implementations. WooCommerce stores can use the dedicated integration to collect subscribers during checkout and send order-related information to EmailOctopus. To use this plugin, you need to create an API key. You can do this via your EmailOctopus account. You can get a free account from the EmailOctopus. The free account allows you to add 2,500 active subscribers and has a few limitations on the account features. These are the features Add EmailOctopus subscription forms using the WordPress Block Editor Integration for Elementor form actions with support for custom list fields WooCommerce integration to collect subscribers and store order-related information in EmailOctopus Add a newsletter subscription checkbox to the WooCommerce checkout Shortcode support for advanced and custom implementations Easy to use, custom list fields will be automatically created if they don’t exist Efficient spam protection (using JavaScript and cookies) The visitor stays on your website while submitting the form data Support for multiple mailing lists (EmailOctopus legacy acoounts) Support for multilingual websites (compatible with Polylang) The form HTML is compatible with the Bootstrap CSS framework Optional: Protect your subscription forms with the plugin WP Armour – Honeypot Anti Spam Optional: Use the CSS style-sheet (Bootstrap compatible) included with the plugin Track successfully submitted forms in Google Analytics and Clicky The plugin includes JS and CSS files only if the form (shortcode or block) is present Using nonces for simple form value validation Developer hooks for adding custom form fields, hidden fields and additional subscription data WooCommerce Checkout Block support The plugin supports the WooCommerce Checkout Block. The EmailOctopus newsletter subscription checkbox can be used with both the classic WooCommerce checkout and the newer block-based checkout. The available checkbox positions are automatically adjusted depending on which checkout type your store uses. Important: If you switch an existing store from the classic checkout to the Checkout Block, please review your EmailOctopus integration settings and thoroughly test the complete checkout process before using it on a live store. The Checkout Block works differently from the classic checkout, and the position and behavior of the newsletter checkbox may change. About EmailOctopus This plugin communicates with the email marketing service EmailOctopus via the API. An active account is required to use this plugin. For more information: Privacy Statement – Privacy Statement – EmailOctopus.com Terms of use – Terms of Use – EmailOctopus.com API – Documentation version 2.0.0 – EmailOctopus.com Block Editor integration The EmailOctopus form block allows you to add a subscription form directly to a page or post using the WordPress Block Editor. Add the ‘EmailOctopus form’ block to your page or post. Select the EmailOctopus mailing list. Configure the form title, description and button label. Choose whether to show the newsletter checkbox and whether the form should use an inline layout. Use the submission settings to configure the thank-you message, source, tags and reporting options. The block uses the general plugin settings as defaults. Additional CSS classes and custom CSS can be added using the standard WordPress block settings. WooCommerce integration If you want to use the EmailOctopus integration for WooCommerce, you need to follow these steps: Go to WooCommerce > Settings > Integrations > EmailOctopus Choose the Mailing list you prefer for the subscription feature on your checkout page Check the other features to include additional order information with each subscription Enable the option “Subscribe everyone” if you like to use EmailOctopus for non-commercial emails (too). Elementor integration If you use Elementor Pro, it’s possible to add the EmailOctopus subscription as form action. Add the Elementor form as usual and choose “EmailOctopus” from “Actions after submit”. Now point the different mailing list fields to the form fields, by entering the field ID. The “Newsletter” option has a special behavior. Use a checkbox in your form and if the checkbox was checked, a tag called “newsletter” will be added to the subscriber in EmailOctopus. Check here the complete documentation for the Block Editor, WooCommerce and Elementor integrations, shortcode options and developer hooks.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C