Description
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Published: 2026-08-20
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GutenKit WordPress plugin, versions 2.4.12 through 2.4.15, contains an insufficient capability check on several of its REST API endpoints. As a result, users who hold the Contributor role or higher are unexpectedly able to retrieve audience metadata from the site’s connected Mailchimp marketing account. This exposure leaks sensitive campaign information, potentially compromising marketing strategy and customer data confidentiality, but does not provide code execution or denial‑of‑service capabilities.

Affected Systems

The vulnerability applies to the GutenKit plugin for WordPress, specifically the 2.4.12 to 2.4.15 releases. Sites running any of these versions with the GutenKit plugin installed are at risk if a contributor or better‑privileged user account exists.

Risk and Exploitability

The CVSS score of 2.7 classifies this issue as low severity, and the EPSS score of less than 1% indicates a very low exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication to the WordPress site and a user role of Contributor or higher, after which an attacker can issue privileged REST API requests to pull audience data. Because the attack vector relies on legitimate user credentials and the plugin’s REST interface, the risk is moderate for users who grant Contributor access to a broad base of contributors.

Generated by OpenCVE AI on August 20, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GutenKit to version 2.5.0 or later, which eliminates the missing capability checks on the REST API endpoints.
  • If an upgrade is not immediately possible, remove the GutenKit plugin from the site to eliminate the exposed endpoints.
  • If removal is not feasible, disable contributor access or restrict it to trusted users until the plugin can be updated to a patched version.

Generated by OpenCVE AI on August 20, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Title GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-20T09:38:10.900Z

Reserved: 2026-08-13T07:59:58.109Z

Link: CVE-2026-19699

cve-icon Vulnrichment

Updated: 2026-08-20T09:36:20.269Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T06:17:13.167

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-19699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:30:05Z

Weaknesses