Laposta Signup Basic

Laposta Signup Basic has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).

Every one of the 2 issues recorded for Laposta Signup Basic has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Nguyen Xuan Chien. Laposta Signup Basic is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Laposta Signup Basic vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3

Laposta Signup Basic <= 1.4.1 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Laposta Signup Basic banner
Latestv3.5.0

Laposta Signup Basic

stijnvanderree

Author

stijnvanderree

5.0(2)
100/100
Last Updated
2026-09-04 (9d ago)
Active Installs
2,000+
Downloads
52,256
Requires WP
4.7+
Requires PHP
7.1+
Tested up to
WP 7.1
Created
2021-04-19 (6y ago)

Laposta is a Dutch email marketing tool. Load your Laposta lists and render fields in a HTML form with custom styling.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C