What the vulnerability does
01Description
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request Forgery.This issue affects AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth: from n/a through 7.3.9.
Explanation of Vulnerability in Simple Terms
02Summary
The AWeber plugin for WordPress fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to, such as form settings or subscriber information. The vulnerability requires an active WordPress account but no special role or admin status. Update to a version newer than 7.3.9.
What an attacker can do
03Attacker Capabilities
Modify form settings, subscriber data, or other protected content without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can alter AWeber forms, landing pages, or subscriber lists, potentially disrupting lead generation or email campaigns.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
November 17, 2023
CVE published
April 28, 2026
Record updated