cleantalk
Vulnerabilities and Security Researches

Mailchimp for WooCommerce, CVE-2026-92435

CVE, Research URL

CVE-2026-92435

Published on
Sep 19, 2026
Research Description
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Affected versions
max 6.1.1.
Status
vulnerable