CVE-2024-10103: Automattic Mailpoet
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
Affected products
- Automattic Mailpoet: before 5.3.2 (fixed in 5.3.2)
Published 2024-11-19. Last modified 2026-06-17.