MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] <= 1.7.18 (unfixed)
unknown
[en] Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.
- Affected:
- up to 1.7.18
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25420 on NVD →
MailerLite – Signup forms (official) <= 1.7.18 - Missing Authorization
medium
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.18. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.7.18
- Fixed in:
- 1.7.19
- Disclosed:
- Jan 28, 2026
CVE-2026-25420 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.17
unknown
[en] The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- Affected:
- up to 1.7.17
- Fixed in:
- 1.7.17
- Disclosed:
- Dec 12, 2025
CVE-2025-13993 on NVD →
MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 5.5
- Affected:
- up to 1.7.16
- Fixed in:
- 1.7.17
- Disclosed:
- Dec 11, 2025
CVE-2025-13993 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.7
unknown
[en] The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contrib...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- May 2, 2024
CVE-2024-1386 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.7
unknown
[en] The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- May 2, 2024
CVE-2024-2797 on NVD →
MailerLite – Signup forms (official) 1.5.0 - 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-...
- CVSS:
- 6.4
- Affected:
- 1.5.0 – 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Apr 29, 2024
CVE-2024-1386 on NVD →
MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization
medium
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated attac...
- CVSS:
- 5.3
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Apr 29, 2024
CVE-2024-2797 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.4
unknown
Update the WordPress Official MailerLite Sign Up Forms plugin to the latest available version (at least 1.4.4).
Dave Jong (Patchstack) discovered and reported this SQL Injection vulnerability in WordPress MailerLite – Signup forms Plugin. This could allow a malicious actor to directly interact with your database, inclu...
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- May 25, 2023
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.5
unknown
Update the WordPress Official MailerLite Sign Up Forms plugin to the latest available version (at least 1.4.5).
Dave Jong (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress MailerLite – Signup forms Plugin. This could allow a malicious actor to force higher privileged...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- May 25, 2023
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.5.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Aug 5, 2022
CVE-2022-33201 on NVD →
MailerLite – Signup forms (official) <= 1.5.7 - Cross-Site Request Forgery
high
The MailerLite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation several functions used to change plugin settings. This makes it possible for unauthenticated attackers to trigger setting updates via forged reque...
- CVSS:
- 8.8
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Aug 1, 2022
CVE-2022-33201 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.5.4
unknown
[en] The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Jun 13, 2022
CVE-2022-1604 on NVD →
MailerLite - Signup forms <= 1.5.3 - Reflected Cross-Site Scripting
medium
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- May 18, 2022
CVE-2022-1604 on NVD →
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.5
unknown
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities found by Dave (WebARX) in WordPress Official MailerLite Sign Up Forms plugin (versions <= 1.4.4).
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- May 25, 2020
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.4
unknown
Unauthenticated SQL Injection (SQLi) vulnerability found by Dave (WebARX) in WordPress Official MailerLite Sign Up Forms plugin (versions <= 1.4.3).
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- May 25, 2020
MailerLite Signup Forms < 1.4.4 - Unauthenticated SQL Injection
critical
The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- May 22, 2020
MailerLite – Signup forms <= 1.4.4 - Cross-Site Request Forgery
medium
The MailerLite – Signup forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to create, modify, or delete signup forms via forged re...
- CVSS:
- 5.4
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- May 22, 2020
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.5
unknown
The MailerLite – Signup forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to create, modify, or delete signup forms via forged re...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- May 22, 2020
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.4
unknown
The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- May 22, 2020
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.5
unknown
Despite fixing the SQL injection, the plugin was still affected by CSRF issues, which could allow an attacker to make a logged in administrator edit, add, and delete arbitrary signup form views.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.4
unknown
Most methods in the MailerLite plugin do not sanitize user input data which causes SQL injection. Also no single method checks for a nonce token which causes a CSRF issue everywhere.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database