CVE-2026-92435
Received Received - Intake

Unauthenticated Admin State Change in Mailchimp for WooCommerce

Vulnerability report for CVE-2026-92435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mailchimp mailchimp_for_woocommerce to 6.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Mailchimp for WooCommerce WordPress plugin before version 6.1.1. It allows unauthenticated users to access administrator-oriented REST API endpoints without proper permission checks. This can lead to unauthorized changes in the plugin's state.

Detection Guidance

Check if the Mailchimp for WooCommerce plugin version is below 6.1.1. Use WordPress admin panel or run a command like 'wp plugin list' if using WP-CLI to verify the installed version.

Impact Analysis

Unauthenticated users could trigger persistent changes in the plugin, potentially altering WooCommerce settings or Mailchimp integrations without authorization. This may disrupt store operations or lead to unintended data handling.

Compliance Impact

This vulnerability could lead to unauthorized data modifications or access, which may violate GDPR (data integrity) or HIPAA (unauthorized changes to health-related data). Compliance risks depend on the specific data processed by the plugin.

Mitigation Strategies

Update the Mailchimp for WooCommerce plugin to version 6.1.1 or later immediately. Disable the plugin temporarily if an update is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92435. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart