CVE · Medium

CVE-2026-25420 — MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-25420 MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.19 Missing Authorization Medium 4.3 < 1.7.19 1.7.19 2026-01-28

CVE-2026-25420

A security flaw exists in the MailerLite – Signup forms (official) plugin for WordPress due to inadequate permission checks on a specific function within all versions up to 1.7.18. As a result, users with contributor or higher privileges can execute unauthorized actions without proper authorization. This vulnerability affects plugin versions through 1.7.18.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.