Junglewise Threat Intelligence

CVE-2026-56063: bPlugins MailChimp Block broken access control

CVE-2026-56063 · Severity: high · CVSS 8.3 · Published 2026-06-26

Vendors: bPlugins.

Executive brief

The MailChimp Block plugin for WordPress, which allows site owners to integrate MailChimp signup forms, contains a security flaw that permits unauthorized access to certain functions. An attacker could exploit this to perform actions on the website that should be restricted to administrators. This could lead to unauthorized changes to site content or configuration, potentially impacting the site's integrity and operations.

Technical details

A broken access control vulnerability exists in the bPlugins MailChimp Block plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. This allows a remote, unauthenticated attacker to execute actions that should be restricted to higher-privileged users. The vulnerability is rated with a CVSS score of 8.3, indicating a high impact on confidentiality, integrity, and availability. The issue is resolved in version 1.1.16.

Affected products

  • bPlugins MailChimp Block <= 1.1.15

Timeline

  • 2026-05-14: disclosed: Reported by researcher Roll
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: patched: NVD publication and patch availability confirmed for version 1.1.16

References