CVE-2026-66703: WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
Published Aug 6, 2026
·Updated
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Affected Software
1 affected component
WordPress MailOptin plugin<=1.2.78.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MailOptin pluginto a version that resolves this vulnerability.Fixed in 1.2.78.1
Event History
Aug 6, 2026
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66703?
CVE-2026-66703 has a medium severity rating of 6.5.
2
What types of attacks can exploit CVE-2026-66703?
CVE-2026-66703 allows for Cross Site Scripting (XSS) attacks.
3
How do I fix CVE-2026-66703?
To fix CVE-2026-66703, update the MailOptin plugin to a version greater than 1.2.78.0.
4
Which versions of the MailOptin plugin are affected by CVE-2026-66703?
CVE-2026-66703 affects the MailOptin plugin versions up to and including 1.2.78.0.
5
What is the impact of exploiting CVE-2026-66703?
Exploiting CVE-2026-66703 can lead to the execution of unauthorized scripts in the context of the victim's browser.