Executive brief
The Simple Membership MailChimp Integration WordPress plugin lacks CSRF protection on its settings page. An attacker can trick a logged-in WordPress administrator into visiting a malicious website that changes the plugin's MailChimp API key to one controlled by the attacker. Once switched, all new member registration data—including names, emails, and membership levels—would be sent to the attacker's account instead of the legitimate one.
Technical details
This is a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress plugin's settings page that lacks nonce validation or CSRF tokens. The attack requires the victim administrator to be logged in to WordPress and click a link or visit a page controlled by the attacker. Once the API key is replaced, subsequent member registrations automatically leak personally identifiable information to the attacker's MailChimp account. The vulnerability affects versions before 1.9.8. A patch is available in version 1.9.8 or later.
Affected products
- Simple Membership MailChimp Integration before 1.9.8
Timeline
- 2026-09-02: disclosed