CVE-2026-25420: WordPress MailerLite plugin <= 1.7.18 - Broken Access Control vulnerability
Published Feb 19, 2026
·Updated
Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.
Affected Software
2 affected components
MailerLite MailerLite<=1.7.18
wordpress/mailerlite<=1.7.18
Event History
Feb 19, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25420?
CVE-2026-25420 is classified as a critical vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2026-25420?
To fix CVE-2026-25420, update the MailerLite plugin to version 1.7.19 or later.
3
What are the implications of CVE-2026-25420?
The implications of CVE-2026-25420 include the risk of unauthorized actions being performed on behalf of users due to broken access controls.
4
Which versions of MailerLite are affected by CVE-2026-25420?
All MailerLite versions up to and including 1.7.18 are affected by CVE-2026-25420.
5
Is CVE-2026-25420 specific to any software?
CVE-2026-25420 specifically affects the MailerLite plugin for WordPress.