Impact
MailMunch – Grow your Email List plugin versions up to and including 3.2.5 contain a broken authentication flaw. The vulnerability allows bypassing the authentication mechanism for subscriber functions, enabling an unauthenticated or hijacked user to perform actions normally restricted to authorized subscribers. This flaw is classified as CWE-288. The impact is potential exposure of subscriber data and unauthorized use of the plugin’s features.
Affected Systems
MailMunch – Grow your Email List up to and including version 3.2.5, a WordPress plugin. Any WordPress site that has one of these plugin versions installed is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not disclosed, and the vulnerability is not listed in the CISA KEV catalog, which suggests no publicly reported widespread exploitation as of now. Attackers can exploit this flaw by accessing subscriber endpoints without valid credentials, so the risk is primarily to confidentiality and integrity of subscriber data.
OpenCVE Enrichment