Input validation vulnerability in MailerLite – Signup forms (official) 1.4.4

The MailerLite Signup Forms plugin for WordPress has a security flaw which could allow an unauthenticated attacker to access sensitive information. This flaw is present in versions up to and including 1.4.3. The flaw exists because the user supplied parameter isn’t properly escaped and the SQL query is not properly prepared. This makes it possible for the attacker to add additional SQL queries, which can be used to extract information from the database.

Detected in:

MailerLite – Signup forms (official) fixed vulnerable versions: >= * < 1.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.