MailerLite – WooCommerce integration <= 3.1.2 - Unauthenticated SQL Injection
high
The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...
- CVSS:
- 7.5
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Jan 20, 2026
CVE-2025-67945 on NVD →
MailerLite – WooCommerce integration < 3.1.3 - Unauthenticated SQL Injection
critical
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Jan 20, 2026
CVE-2025-67945 on NVD →
MailerLite - WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion
medium
The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level a...
- CVSS:
- 6.5
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Dec 15, 2025
CVE-2026-1000 on NVD →
MailerLite - WooCommerce integration < 3.1.4 - Missing Authorization to Data Deletion
medium
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Dec 15, 2025
CVE-2026-1000 on NVD →
MailerLite – WooCommerce integration <= 2.0.8 - Cross-Site Request Forgery via Multiple AJAX Functions
medium
The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a f...
- CVSS:
- 5.4
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Jan 8, 2024
CVE-2023-52223 on NVD →
MailerLite – WooCommerce integration <= 2.0.8 - Missing Authorization via Multiple Functions
medium
The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unautho...
- CVSS:
- 4.3
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Jan 8, 2024
CVE-2023-52227 on NVD →
MailerLite – WooCommerce integration < 2.0.9 - Cross-Site Request Forgery via Multiple AJAX Functions
medium
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Jan 8, 2024
CVE-2023-52223 on NVD →
MailerLite – WooCommerce integration < 2.0.9 - Missing Authorization via Multiple Functions
medium
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Jan 8, 2024
CVE-2023-52227 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database