CVE-2026-92435
Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
| Vendor | unknown |
| Product | mailchimp for woocommerce |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mailchimp for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown mailchimp for woocommerce are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Mailchimp for WooCommerce
0 < 6.1.1
References
Credits
Pablo González and Francisco José Ramírez WPScan