Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms. | |
| Title | MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-24T14:34:00.566Z
Reserved: 2026-02-26T11:29:13.850Z
Link: CVE-2026-3253
Updated: 2026-09-24T14:33:57.475Z
Status : Deferred
Published: 2026-09-24T12:17:12.160
Modified: 2026-09-24T15:17:21.977
Link: CVE-2026-3253
No data.
OpenCVE Enrichment
Updated: 2026-09-24T12:30:18Z