Extension WordPress
Vulnérabilités MailerLite – Signup forms (official)
Cette page rassemble les failles publiées pour MailerLite – Signup forms (official), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MailerLite – Signup forms (official)
8 fiches
MailerLite – Signup forms (official) <= 1.7.18 – Missing Authorization
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.18. This makes it possible for authenticated attackers,…
*-1.7.18
1.7.19
28/01/2026
MailerLite – Signup forms (official) <= 1.7.16 – Authenticated (Administrator+) Stored Cross-Site Scripting
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_description' and 'success_message' parameters in versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes…
*-1.7.16
1.7.17
11/12/2025
MailerLite – Signup forms (official) <= 1.7.6 – Missing Authorization
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes…
*-1.7.6
1.7.7
29/04/2024
MailerLite – Signup forms (official) 1.5.0 – 1.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
1.5.0-1.7.6
1.7.7
29/04/2024
MailerLite – Signup forms (official) <= 1.5.7 – Cross-Site Request Forgery
The MailerLite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation several functions used to change plugin settings. This makes it possible…
*-1.5.7
1.5.8
01/08/2022
MailerLite – Signup forms <= 1.5.3 – Reflected Cross-Site Scripting
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
*-1.5.3
1.5.4
18/05/2022
MailerLite – Signup forms <= 1.4.4 – Cross-Site Request Forgery
The MailerLite – Signup forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for…
[*, 1.4.5)
1.4.5
22/05/2020
MailerLite Signup Forms < 1.4.4 – Unauthenticated SQL Injection
The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
[*, 1.4.4)
1.4.4
22/05/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.