Executive brief
The Mailercloud plugin for WordPress, which connects website forms to the Mailercloud marketing platform, contains a security flaw in its access control. An unauthorized user could potentially perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes in how website contacts are synchronized or how webforms function.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Mailercloud – Integrate webforms and synchronize website contacts plugin for WordPress. The flaw is present in versions up to and including 1.0.7 and stems from a failure to implement proper permission checks or nonce validation on certain functions. An unauthenticated remote attacker can exploit this to execute actions that should be restricted to higher-privileged users, potentially leading to unauthorized data modification or configuration changes. The issue is addressed in version 1.0.8.
Affected products
- mailercloud Mailercloud – Integrate webforms and synchronize website contacts <= 1.0.7
Timeline
- 2026-01-31: other: Vulnerability reported by researcher Nabil Irawan
- 2026-03-02: advisory: Patchstack published advisory details
- 2026-03-02: patched: Version 1.0.8 released to address the vulnerability
- 2026-04-08: disclosed: CVE published to NVD