plugin

Woo Mailerlite Vulnerabilities

8 known security issues reported for the Woo Mailerlite WordPress plugin. Most recent disclosed Jan 20, 2026.

1 critical 1 high 6 medium

Running Woo Mailerlite on your site? Check whether your installed version is affected.

Scan your site free

MailerLite – WooCommerce integration <= 3.1.2 - Unauthenticated SQL Injection

high

The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...

CVSS:
7.5
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Jan 20, 2026

CVE-2025-67945 on NVD →

MailerLite – WooCommerce integration < 3.1.3 - Unauthenticated SQL Injection

critical
Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jan 20, 2026

CVE-2025-67945 on NVD →

MailerLite - WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion

medium

The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level a...

CVSS:
6.5
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Dec 15, 2025

CVE-2026-1000 on NVD →

MailerLite - WooCommerce integration < 3.1.4 - Missing Authorization to Data Deletion

medium
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Dec 15, 2025

CVE-2026-1000 on NVD →

MailerLite – WooCommerce integration <= 2.0.8 - Cross-Site Request Forgery via Multiple AJAX Functions

medium

The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a f...

CVSS:
5.4
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Jan 8, 2024

CVE-2023-52223 on NVD →

MailerLite – WooCommerce integration <= 2.0.8 - Missing Authorization via Multiple Functions

medium

The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unautho...

CVSS:
4.3
Affected:
up to 2.0.8
Fixed in:
2.0.9
Disclosed:
Jan 8, 2024

CVE-2023-52227 on NVD →

MailerLite – WooCommerce integration < 2.0.9 - Cross-Site Request Forgery via Multiple AJAX Functions

medium
Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Jan 8, 2024

CVE-2023-52223 on NVD →

MailerLite – WooCommerce integration < 2.0.9 - Missing Authorization via Multiple Functions

medium
Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Jan 8, 2024

CVE-2023-52227 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database