CVE-2026-3253: MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms.
Affected Software
Event History
Frequently Asked Questions
Which users could exploit this issue?
Any authenticated WordPress user with the Contributor role or a higher-privileged role could exploit it. Unauthenticated visitors are not identified as able to exploit the issue.
What access does an attacker need, and what can they do?
The attacker needs a valid WordPress account with at least Contributor-level access. They can create or delete arbitrary MailerLite signup forms.
Are installations running version 1.7.21 affected?
Yes. The affected versions include 1.7.21 and all earlier versions.