CVE-2024-10103: Automattic Mailpoet

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

Affected products

  • Automattic Mailpoet: before 5.3.2 (fixed in 5.3.2)

Published 2024-11-19. Last modified 2026-06-17.