What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
Explanation of Vulnerability in Simple Terms
The MailerLite WordPress plugin version 1.5.7 and earlier is vulnerable to cross-site request forgery (CSRF). An attacker can trick a logged-in site administrator into performing unwanted actions, such as changing plugin settings or modifying email campaigns. The vulnerability requires the admin to visit a malicious webpage while authenticated to the WordPress site.
What an attacker can do
Trick an authenticated admin into performing unwanted actions on the site via a malicious webpage.
Potential impact on your site
An attacker could modify MailerLite plugin settings or email campaigns without your knowledge if you click a malicious link while logged in.
Conditions required to exploit
Admin must be logged into WordPress and visit an attacker-controlled page while authenticated.
Key dates
External resources
Related vulnerabilities