Impact
The GutenKit WordPress plugin, versions 2.4.12 through 2.4.15, contains an insufficient capability check on several of its REST API endpoints. As a result, users who hold the Contributor role or higher are unexpectedly able to retrieve audience metadata from the site’s connected Mailchimp marketing account. This exposure leaks sensitive campaign information, potentially compromising marketing strategy and customer data confidentiality, but does not provide code execution or denial‑of‑service capabilities.
Affected Systems
The vulnerability applies to the GutenKit plugin for WordPress, specifically the 2.4.12 to 2.4.15 releases. Sites running any of these versions with the GutenKit plugin installed are at risk if a contributor or better‑privileged user account exists.
Risk and Exploitability
The CVSS score of 2.7 classifies this issue as low severity, and the EPSS score of less than 1% indicates a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication to the WordPress site and a user role of Contributor or higher, after which an attacker can issue privileged REST API requests to pull audience data. Because the attack vector relies on legitimate user credentials and the plugin’s REST interface, the risk is moderate for users who grant Contributor access to a broad base of contributors.
OpenCVE Enrichment