PT-2026-84746 · WordPress · Simple Membership Mailchimp Integration
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Membership MailChimp Integration versions prior to 1.9.8
Description
The settings page of the plugin lacks Cross-Site Request Forgery (CSRF) checks, which is a type of attack that forces an authenticated user to execute unwanted actions. This allows an attacker to trick a logged-in administrator into modifying the configured third-party API key. Consequently, all subsequent member registration data, including name, email, and membership level, is transmitted to an account controlled by the attacker.
Recommendations
Update Simple Membership MailChimp Integration to version 1.9.8 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Membership Mailchimp Integration