CVE-2025-58596: WordPress MailOptin Plugin <= 1.2.75.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin mailoptin allows Stored XSS.This issue affects MailOptin: from n/a through <= 1.2.75.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58596?
CVE-2025-58596 is considered a critical vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-58596?
To fix CVE-2025-58596, update Properfraction MailOptin to a version above 1.2.75.0 to mitigate the risk of this vulnerability.
What impact does CVE-2025-58596 have on user data?
CVE-2025-58596 could allow attackers to execute scripts in user sessions, potentially exposing sensitive user data.
Is CVE-2025-58596 present in earlier versions of MailOptin?
Yes, CVE-2025-58596 affects all versions of Properfraction MailOptin up to and including 1.2.75.0.
Who is affected by CVE-2025-58596?
Any users of Properfraction MailOptin or WordPress MailOptin versions up to 1.2.75.0 are affected by this vulnerability.