Impact
The MailChimp Forms by MailMunch plugin contains a missing capability check on the sign_in() and sign_up() AJAX actions. An attacker who has already authenticated with a Subscriber or higher role can submit fake credentials to these endpoints and force the plugin to associate the site’s MailMunch integration with the attacker's account. Once relinked, every piece of subscriber data collected by the site’s forms is sent to the attacker’s account, and any forms or landing pages displayed on the site are loaded from the attacker’s MailMunch configuration. This type of flaw constitutes a broken access control that can compromise subscriber confidentiality and the integrity of the site’s form content.
Affected Systems
WordPress sites that have the Mailmunch Forms for Mailchimp plugin installed, version 3.2.7 or earlier. All installations of the plugin before the fix are vulnerable and can be impacted by an authenticated user with Subscriber or higher privileges.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. Exploit probability data (EPSS) is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated with at least Subscriber-level access to trigger the vulnerable AJAX actions, and then can execute the malicious re‑link by providing forged credentials. The risk is therefore high for sites that rely on the plugin for collecting subscriber data, as the attacker can both harvest information and alter the presentation of forms on the site.
OpenCVE Enrichment