Junglewise Threat Intelligence

CVE-2026-92435: Mailchimp for WooCommerce missing authorization in REST API

CVE-2026-92435 · Severity: medium · CVSS 5.3 · Published 2026-09-19

Executive brief

The Mailchimp for WooCommerce WordPress plugin fails to properly verify user permissions on several REST API endpoints, allowing unauthenticated attackers to access administrator functions and make persistent changes to store configuration. This could enable unauthorized modifications to email marketing settings, customer data, or other critical store parameters without authentication.

Technical details

A broken access control vulnerability (CWE-862) in the REST API permission callbacks allows unauthenticated requests to reach admin-oriented endpoints. The plugin does not verify the required capabilities before processing requests on multiple API routes, enabling an attacker with network access to trigger persistent state changes without prior authentication.

Affected products

  • Mailchimp Mailchimp for WooCommerce before 6.1.1

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: patched: Fixed in version 6.1.1

References

Related threats