Inboxify Sign Up Form
Inboxify Sign Up Form has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Inboxify Sign Up Form has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Nur Ibnu Hubab. Inboxify Sign Up Form is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2025-69008Inboxify Sign Up Form <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Inboxify Sign Up Form
Author
Inboxify
Inboxify is an online application for sending email newsletters. Many companies, mostly from the Netherlands, make use of Inboxify for sending newsletters to their customers and relations. At the moment, Inboxify is only available in Dutch. With the Inboxify Sign Up Form plugin you can add sign up forms and checkboxes to your WordPress website to enable your visitors to sign up directly to your Inboxify list. Features Easy to use Sign Up Form Widget Add a sign up form to your posts and pages using the shortcode [inboxify_subscribe] Add a subscribe checkbox to your comment form, registration form or user profile form Prevent spam submissions using one of the supported CAPTCHA plugins Compatible with the “Really Simple CAPTCHA”, “SI CAPTCHA Anti-Spam” and “WordPress ReCaptcha Integration” plugins AJAX form processing
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C