MailPoet Newsletters (Previous)

MailPoet Newsletters (Previous) has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2018; all 10 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2016 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (40%). Other recurring categories include SQL Injection, Authorization Bypass Through User-Controlled Key.

Every one of the 10 issues recorded for MailPoet Newsletters (Previous) has a vendor fix available, so running the current release closes all known holes.

8 independent researchers contributed these findings, one record each.

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

10

Get automatic notifications for all MailPoet Newsletters (Previous) vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2014-4725

MailPoet Newsletters <= 2.6.6 - Arbitrary File Upload

Read the full analysis

Vulnerability Records

10 records
2018-03-14 00:00CVE-2018-20853
5.3
Medium
AnonymousYes
2016-09-11 00:00N/A
6.5
Medium
AnonymousYes
2016-09-10 00:00N/A
6.5
Medium
Sipke MellemaYes
2016-02-02 00:00N/A
6.1
Medium
Omar KurtYes
2014-09-21 00:00CVE-2014-4726
7.3
High
DominicYes
2014-09-21 00:00CVE-2014-3907
6.3
Medium
Yoshinori MatsumotoYes
2014-08-01 00:00CVE-2014-4725
9.8
Critical
Sucuri Research TeamYes
2013-02-03 00:00CVE-2013-1408
7.2
High
High-Tech Bridge Security Research LabYes
2012-11-22 00:00N/A
6.1
Medium
Ryan DewhurstYes
2012-11-09 20:12CVE-2012-3414
6.1
Medium
Neal PooleYes
Showing 1–10 of 10 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C