CVE 6.5 MEDIUM

MailerLite – WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion_CVE-2026-1000

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's integration settings, delete all plugin options, and drop the plugin's database tables (woo_mailerlite_carts and woo_mailerlite_jobs), resulting in complete loss of plugin data including customer abandoned cart information and sync job history.

Basic Information

ID CVE-2026-1000
Source Wordfence
Published Jan 16, 2026 at 04:44

Affected Product

Vendor mailerlite
Product MailerLite – WooCommerce integration
Version *
Affected Versions mailerlite MailerLite – WooCommerce integration *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.