CVE-2026-57626: WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Jul 23, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0.
Affected Software
1 affected component
MailPoet MailPoet>=5.30.0<=5.33.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MailPoet pluginto a version that resolves this vulnerability.Fixed in 5.33.1
Event History
Jul 23, 2026
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57626?
CVE-2026-57626 is rated with a high severity level of 7.1.
2
What type of vulnerability is CVE-2026-57626?
CVE-2026-57626 is a Cross Site Request Forgery (CSRF) vulnerability.
3
How do I fix CVE-2026-57626?
To fix CVE-2026-57626, update the MailPoet plugin to versions beyond 5.33.0.
4
Which versions of MailPoet are affected by CVE-2026-57626?
CVE-2026-57626 affects MailPoet versions from 5.30.0 through 5.33.0.
5
What impact does CVE-2026-57626 have on my website?
CVE-2026-57626 can enable unauthorized actions on behalf of authenticated users, compromising website security.