MailerLite – WooCommerce integration
MailerLite – WooCommerce integration has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection.
Every one of the 4 issues recorded for MailerLite – WooCommerce integration has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. MailerLite – WooCommerce integration is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-67945MailerLite – WooCommerce integration <= 3.1.2 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

MailerLite – WooCommerce integration
Author
MailerLite
woocommercePowerful e-commerce email marketing tools that are easy to use. Grow your store with automated emails, pop-ups, product blocks, sales tracking + more. OFFICIAL PLUGIN FEATURES Checkout integration Select between multiple positions Show/hide checkbox Enable/disable double opt-in Product importing Sales tracking and campaign ROI Customize checkbox label via settings page Forward order data to MailerLite Setup order tracking MailerLite custom fields Setup order related MailerLite segments Set up automation triggered by recent purchases Abandoned cart emails Subscribe pop-ups Regular updates and improvements: Check out the changelog Quickstart Enter your MailerLite API key For e-commerce tracking on campaigns generate a consumer key + secret with read rights Select your default list/group Enable checkout integration Credits Plugin created with the official MailerLite API.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C