Description
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Access to Administrative API
Action: Immediate Patch
AI Analysis

Impact

The Mailchimp for WooCommerce plugin contains an access control flaw that fails to verify a user’s capability before handling several REST API routes. This omission permits unauthenticated users to invoke administrative endpoints, resulting in persistent state changes such as modifying subscriber lists or integration settings. The flaw corresponds to CWE‑862 (Missing Authorization) and can compromise the integrity of a WordPress site's e‑commerce functions.

Affected Systems

WordPress sites that have the Mailchimp for WooCommerce plugin installed at any version before 6.1.1 are affected. No specific vendor‑provided version list is given, but any deployment of the plugin older than 6.1.1 is vulnerable.

Risk and Exploitability

The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of known exploits. The CVSS score of 5.3 reflects moderate severity, while the flaw allows arbitrary state changes via public REST requests. The potential impact on data integrity and customer experience is significant, and an attacker can simply issue HTTP requests to the exposed endpoints without authentication, making exploitation straightforward if the site is accessible over the internet.

Generated by OpenCVE AI on September 20, 2026 at 02:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mailchimp for WooCommerce to version 6.1.1 or later.
  • Restrict or disable the plugin’s REST API endpoints for unauthenticated users, for example by configuring a firewall rule or using a WordPress REST API control plugin.
  • Regularly review plugin versions, stay informed about vendor advisories, and monitor access logs for unusual REST API activity.

Generated by OpenCVE AI on September 20, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions mailchimp For Woocommerce
Vendors & Products Wordpress-extensions
Wordpress-extensions mailchimp For Woocommerce

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Title Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
References

Subscriptions

Wordpress-extensions Mailchimp For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:16:26.790Z

Reserved: 2026-09-16T10:14:50.138Z

Link: CVE-2026-92435

cve-icon Vulnrichment

Updated: 2026-09-19T13:10:05.687Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:34.333

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-92435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:10Z

Weaknesses