Executive brief
The Campaign Monitor plugin for WordPress, which integrates email marketing forms into websites, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to access. While the impact is considered low, it could allow unauthorized changes to plugin configurations or data.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Campaign Monitor for WordPress plugin through version 2.9.1. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An authenticated attacker with Subscriber-level privileges can exploit this over the network to perform unauthorized actions or modify settings. The issue is addressed in version 2.9.2.
Affected products
- Campaign Monitor Campaign Monitor for WordPress n/a through 2.9.1
Timeline
- 2025-12-09: other: Reported by Nabil Irawan
- 2026-01-08: disclosed
- 2026-01-08: advisory