CVE-2024-8628(mailoptin / mailoptin)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mailoptin

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mailoptin

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Referenced assets1 URL
Full discourse1 post
  • SHELLCODE@sh3ll_c0d3

    🏭 OT SECURITY: Rockwell ControlLogix Safety PLC DoS (CVE-2024-8628)! ⚡️🔧 CISA issues alert on CIP packet exhaustion flaw forcing Allen-Bradley PLCs into unrecoverable faults. 👉 ICS Guide: https://sh3llc0d3.com/blog/rockwell-automation-controllogix-plc-resource-exhaustion-analyzing-cve-2024-8628-and-cip-protocol-vulnerabilities/ #sh3llc0d3 #SCADA #ICS #PLC

    0000029
    106 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmailoptinmailoptin-wordpress-

Explore more