rootpwn

medium · CVSS v3 5.3 · EPSS 0.00136

CVE-2026-92435

The Mailchimp for WooCommerce WordPress plugin before version 6.1.1 fails to properly verify user capabilities within the permission callbac

Overview

The Mailchimp for WooCommerce WordPress plugin before version 6.1.1 fails to properly verify user capabilities within the permission callbacks for multiple REST API routes. This oversight allows unauthenticated attackers to access administrator-oriented endpoints and make persistent state changes.

Description

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.

Impact

This vulnerability impacts confidentiality and integrity by exposing administrative endpoints to unauthenticated users, potentially allowing unauthorized state modifications. Website administrators and site owners face a moderate risk of unauthorized configuration changes or data exposure within the affected WordPress environment.

Remediation

Update the Mailchimp for WooCommerce plugin to version 6.1.1 or later where the missing permission callback checks have been resolved. Regularly audit WordPress REST API access logs for unusual requests directed at plugin-specific endpoints, and enforce the principle of least privilege across all user roles.

Risk context

This vulnerability is rated as medium severity with a CVSS score of 5.3 and a low EPSS score of 0.00136. While it requires no authentication, remediation can be achieved promptly by applying the vendor-supplied plugin update.

Affected products

  • Mailchimp for WooCommerce WordPress plugin

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS
0.00136

wordpress plugin rest-api missing-authorization unauthenticated mailchimp

← All CVEs