Vulnerabilities and security researches forofficial-mailerlite-sign-up-forms official-mailerlite-sign-up-forms
Direction: ascendingJun 07, 2024
MailerLite – Signup forms (official) # 7d2bf278e464f24994e0657790edb3a0f328acc5
- CVE, Research URL
- Application
- Date
- May 25, 2020
- Research Description
- MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.4.5 (closed) WordPress Official MailerLite Sign Up Forms plugin <= 1.4.3 - Unauthenticated SQL Injection (SQLi) vulnerability Unauthenticated SQL Injection (SQLi) vulnerability found by Dave (WebARX) in WordPress Official MailerLite Sign Up Forms plugin (versions <= 1.4.3).
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
MailerLite – Signup forms (official) # CVE-2022-1604
- CVE, Research URL
- Application
- Date
- Jun 13, 2022
- Research Description
- The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 1.5.4.
- Status
-
vulnerable
MailerLite – Signup forms (official) # CVE-2022-33201
- CVE, Research URL
- Application
- Date
- Aug 05, 2022
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
- Affected versions
-
max 1.4.5.
- Status
-
vulnerable
MailerLite – Signup forms (official) # CVE-2024-2797
- CVE, Research URL
- Application
- Date
- May 02, 2024
- Research Description
- The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated attackers to allow lower level users to modify forms.
- Affected versions
-
max 1.7.7.
- Status
-
vulnerable
MailerLite – Signup forms (official) # CVE-2024-1386
- CVE, Research URL
- Application
- Date
- May 02, 2024
- Research Description
- The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.7.7.
- Status
-
vulnerable
Jan 09, 2026
MailerLite – Signup forms (official) # CVE-2025-13993
- CVE, Research URL
- Application
- Date
- Dec 12, 2025
- Research Description
- The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.7.17.
- Status
-
vulnerable