Unauthorized Data Modification in MailerLite Signup Forms for WordPress
CVE-2026-3253
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
What is CVE-2026-3253?
The MailerLite Signup Forms plugin for WordPress is susceptible to unauthorized data modification owing to the absence of a capability check in the forms() method of the AdminController class in all versions up to and including 1.7.21. This vulnerability permits authenticated attackers with Contributor-level access or higher to create or delete any signup forms, thereby compromising data integrity and potentially affecting user interactions.
Affected Version(s)
MailerLite – Signup forms (official) 0 <= 1.7.21