CVE-2023-47757: Aweber

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth allows Accessing Functionality Not Properly Constrained by ACLs, Cross-Site Request Forgery.This issue affects AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth: from n/a through 7.3.9.

Affected products

  • Aweber Aweber: before 7.3.10 (fixed in 7.3.10)

Published 2023-11-17. Last modified 2026-06-17.