{"id":"CVE-2026-3253","title":"The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…","summary":"The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"mailerlite","product":"MailerLite – Signup forms (official)","affected":["signup_forms_official <= 1.7.21"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T15:17:21.977","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3253","references":[{"url":"https://plugins.trac.wordpress.org/changeset/3505999/","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1d845767-1e5f-43f0-9fc6-a897c2d5c3dd?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T14:33:53.170720Z"},"ingestedAt":"2026-09-24T11:42:06.845Z","slug":"CVE-2026-3253","body":"## Overview\n\nThe MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}