Mailchimp for WooCommerce < 6.2 - Authenticated (Administrator+) SQL Injection
medium
The Mailchimp for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above,...
- CVSS:
- 4.9
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Aug 12, 2026
CVE-2026-73346 on NVD →
Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.1
unknown
[en] The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for e...
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- Aug 29, 2022
CVE-2022-2267 on NVD →
Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2
unknown
[en] The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.2
- Disclosed:
- Aug 29, 2022
CVE-2022-2556 on NVD →
Mailchimp for WooCommerce <= 2.7.1 - Authenticated (Admin+) Server-Side Request Forgery
medium
The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX actions in versions up to, and including, 2.7.1. This makes it possible for an attacker with administrator privileges to send requests to the internal network.
- CVSS:
- 4.9
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Aug 3, 2022
CVE-2022-2556 on NVD →
Mailchimp for WooCommerce <= 2.7 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX actions in versions up to, and including, 2.7.1. This makes it possible for an attacker with subscriber privileges or higher to send requests to the internal network.
- CVSS:
- 4.3
- Affected:
- up to 2.7
- Fixed in:
- 2.7.1
- Disclosed:
- Aug 3, 2022
CVE-2022-2267 on NVD →
Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.1.2
unknown
WordPress MailChimp for WooCommerce plugin is prone to a Local File Inclusion vulnerability in 2.1.2 version. The vulnerability was in /admin/partials/tabs/notices.php file in if ( isset ( $_GET['error_notice'] ) ... IF conditional statement which lead to include(__DIR__.'/errors/'.$_GET['error_notice'].'.php'); loc...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Nov 22, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database