Impact
The affected WordPress plugin lacks CSRF validation on its settings page, allowing an attacker to trick a logged‑in administrator into replacing the stored MailChimp API key. Once changed, all future member registrations—including name, email, and membership level—are sent to the attacker’s MailChimp account, compromising confidentiality of user data.
Affected Systems
Any WordPress site running Simple Membership MailChimp Integration older than version 1.9.8 and with an administrator role able to access the plugin’s settings.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The absence of an EPSS score and lack of KEV listing reduce certainty of active exploitation, but the vulnerability can be exploited remotely via a crafted CSRF request, requiring only that the attacker deliver a malicious link to an authenticated administrator. Once executed, it enables continuous exfiltration without further interaction.
OpenCVE Enrichment