Description
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MailChimp Forms by MailMunch plugin contains a missing capability check on the sign_in() and sign_up() AJAX actions. An attacker who has already authenticated with a Subscriber or higher role can submit fake credentials to these endpoints and force the plugin to associate the site’s MailMunch integration with the attacker's account. Once relinked, every piece of subscriber data collected by the site’s forms is sent to the attacker’s account, and any forms or landing pages displayed on the site are loaded from the attacker’s MailMunch configuration. This type of flaw constitutes a broken access control that can compromise subscriber confidentiality and the integrity of the site’s form content.

Affected Systems

WordPress sites that have the Mailmunch Forms for Mailchimp plugin installed, version 3.2.7 or earlier. All installations of the plugin before the fix are vulnerable and can be impacted by an authenticated user with Subscriber or higher privileges.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. Exploit probability data (EPSS) is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated with at least Subscriber-level access to trigger the vulnerable AJAX actions, and then can execute the malicious re‑link by providing forged credentials. The risk is therefore high for sites that rely on the plugin for collecting subscriber data, as the attacker can both harvest information and alter the presentation of forms on the site.

Generated by OpenCVE AI on August 5, 2026 at 09:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Mailmunch Forms for Mailchimp to version 3.2.8 or later, which restores proper capability checks on the sign_in() and sign_up() AJAX handlers.
  • If an immediate update is not possible, limit AJAX access to only administrators or users with explicit capabilities to manage integrations, and prevent regular subscribers from performing the sign_in() or sign_up() actions.
  • Verify the current MailMunch integration account for each site; if it appears to belong to an unfamiliar or compromised account, re‑authenticate using a legitimate account and review the form and landing page content for integrity.

Generated by OpenCVE AI on August 5, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mailmunch
Mailmunch mailmunch Forms For Mailchimp
Wordpress
Wordpress wordpress
Vendors & Products Mailmunch
Mailmunch mailmunch Forms For Mailchimp
Wordpress
Wordpress wordpress

Wed, 05 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
Title MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Mailmunch Mailmunch Forms For Mailchimp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-05T13:11:29.519Z

Reserved: 2026-04-30T16:42:06.998Z

Link: CVE-2026-7520

cve-icon Vulnrichment

Updated: 2026-08-05T13:11:22.472Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T08:16:44.560

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-7520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:17:48Z

Weaknesses