CVE-2023-47757 MEDIUM

CVE-2023-47757: WordPress AWeber Plugin <= 7.3.9 is vulnerable to Broken Access Control

Vendor Aweber
Product AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth
Weakness CWE-862 · Missing authorization
Published November 17, 2023
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request Forgery.This issue affects AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth: from n/a through 7.3.9.

Explanation of Vulnerability in Simple Terms

02Summary

The AWeber plugin for WordPress fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to, such as form settings or subscriber information. The vulnerability requires an active WordPress account but no special role or admin status. Update to a version newer than 7.3.9.

What an attacker can do

03Attacker Capabilities

Modify form settings, subscriber data, or other protected content without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can alter AWeber forms, landing pages, or subscriber lists, potentially disrupting lead generation or email campaigns.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

November 17, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE