CVE-2022-33201: WordPress MailerLite – Signup forms (official) plugin <= 1.5.7 - Cross-Site Request Forgery (CSRF) vulnerability
Published Aug 5, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
Affected Software
1 affected component
MailerLite Mailerlite Signup Forms Wordpress<1.5.8
Remediation
Information
Update to 1.5.8 or higher version.
Event History
Aug 5, 2022
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-33201?
CVE-2022-33201 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2022-33201?
To fix CVE-2022-33201, update the MailerLite Signup Forms plugin to version 1.5.8 or later.
3
What systems are affected by CVE-2022-33201?
CVE-2022-33201 affects the MailerLite Signup Forms plugin for WordPress versions 1.5.7 and earlier.
4
What can an attacker do with CVE-2022-33201?
An attacker exploiting CVE-2022-33201 can change the API key, potentially compromising the MailerLite configuration.
5
Is there a patch available for CVE-2022-33201?
Yes, the patch for CVE-2022-33201 is included in the MailerLite Signup Forms plugin version 1.5.8.