Laposta Signup Basic
Laposta Signup Basic has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).
Every one of the 2 issues recorded for Laposta Signup Basic has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Nguyen Xuan Chien. Laposta Signup Basic is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Laposta Signup Basic <= 1.4.1 - Missing Authorization
Read the full analysisVulnerability Records

Laposta Signup Basic
Author
stijnvanderree
Laposta is a Dutch email marketing tool. Load your Laposta lists and render fields in a HTML form with custom styling.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C