Impact
The Mailchimp for WooCommerce plugin contains an access control flaw that fails to verify a user’s capability before handling several REST API routes. This omission permits unauthenticated users to invoke administrative endpoints, resulting in persistent state changes such as modifying subscriber lists or integration settings. The flaw corresponds to CWE‑862 (Missing Authorization) and can compromise the integrity of a WordPress site's e‑commerce functions.
Affected Systems
WordPress sites that have the Mailchimp for WooCommerce plugin installed at any version before 6.1.1 are affected. No specific vendor‑provided version list is given, but any deployment of the plugin older than 6.1.1 is vulnerable.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of known exploits. The CVSS score of 5.3 reflects moderate severity, while the flaw allows arbitrary state changes via public REST requests. The potential impact on data integrity and customer experience is significant, and an attacker can simply issue HTTP requests to the exposed endpoints without authentication, making exploitation straightforward if the site is accessible over the internet.
OpenCVE Enrichment