Impact
An SQL injection flaw exists in the WordPress MailChimp For WooCommerce plugin version less than 6.2. The defect allows an authenticated administrator to inject arbitrary SQL into database queries. This can lead to data theft, modification, or deletion, compromising confidentiality, integrity, and availability of the site’s data. The weakness is a classic input validation failure, classified as CWE-89.
Affected Systems
The vulnerability affects WordPress sites that have the MailChimp For WooCommerce plugin installed at any version prior to 6.2. The affected vendor is Mailchimp, product MailChimp For WooCommerce. No specific WordPress core or PHP versions are listed.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. EPSS is not reported, so the current exploitation probability is unknown. Since the vulnerability is not listed in CISA KEV, it is not known to be actively exploited. An attacker would need to authenticate as an administrator, but many sites leave the admin role exposed or poorly protected. The likely attack surface is through the plugin’s administrative interface, where unsanitized input is passed to the database.
OpenCVE Enrichment