CVE-2026-56063
Deferred Deferred - Pending Action
Unauthenticated Broken Access Control in MailChimp Block

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack mailchimp_block_plugin to 1.1.16 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-56063 is a Broken Access Control vulnerability in the WordPress MailChimp Block Plugin versions 1.1.15 and earlier.

This vulnerability allows unauthenticated users to perform actions with higher privileges because the plugin lacks proper authorization, authentication, or nonce token checks.

It is classified as a high-risk issue with a CVSS score of 8.3 and falls under the OWASP Top 10 category A1: Broken Access Control.

Impact Analysis

This vulnerability can allow attackers to perform unauthorized actions on affected websites without needing to authenticate.

Because the vulnerability affects thousands of websites using the vulnerable plugin versions, exploitation could lead to data manipulation, service disruption, or unauthorized access to sensitive information.

The impact includes potential loss of confidentiality, integrity, and availability of the affected systems.

Detection Guidance

The vulnerability in the WordPress MailChimp Block Plugin versions 1.1.15 and earlier is due to missing authorization, authentication, or nonce token checks, allowing unauthenticated users to perform privileged actions.

There is no specific detection command or network signature provided in the available resources.

However, monitoring for unusual or unauthorized access attempts to the MailChimp Block plugin endpoints or suspicious HTTP requests targeting the plugin could help identify exploitation attempts.

Mitigation Strategies

Immediate mitigation steps include updating the WordPress MailChimp Block Plugin to version 1.1.16 or later, where the vulnerability has been patched.

Until the update can be applied, it is recommended to implement the mitigation rule provided by Patchstack to block attacks targeting this vulnerability.

Compliance Impact

The vulnerability in the MailChimp Block plugin allows unauthenticated users to bypass access controls, potentially leading to unauthorized access to sensitive data or functionality.

Such unauthorized access could result in violations of data protection regulations like GDPR or HIPAA, which require strict controls over access to personal and sensitive information.

Therefore, if exploited, this vulnerability may compromise compliance with these standards by failing to adequately protect data confidentiality, integrity, and availability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart