plugin

Mailchimp For Woocommerce Vulnerabilities

6 known security issues reported for the Mailchimp For Woocommerce WordPress plugin. Most recent disclosed Aug 12, 2026.

3 medium

Running Mailchimp For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Mailchimp for WooCommerce < 6.2 - Authenticated (Administrator+) SQL Injection

medium

The Mailchimp for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above,...

CVSS:
4.9
Affected:
up to 6.2
Fixed in:
6.2
Disclosed:
Aug 12, 2026

CVE-2026-73346 on NVD →

Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.1

unknown

[en] The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for e...

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Aug 29, 2022

CVE-2022-2267 on NVD →

Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2

unknown

[en] The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Aug 29, 2022

CVE-2022-2556 on NVD →

Mailchimp for WooCommerce <= 2.7.1 - Authenticated (Admin+) Server-Side Request Forgery

medium

The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX actions in versions up to, and including, 2.7.1. This makes it possible for an attacker with administrator privileges to send requests to the internal network.

CVSS:
4.9
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Aug 3, 2022

CVE-2022-2556 on NVD →

Mailchimp for WooCommerce <= 2.7 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX actions in versions up to, and including, 2.7.1. This makes it possible for an attacker with subscriber privileges or higher to send requests to the internal network.

CVSS:
4.3
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Aug 3, 2022

CVE-2022-2267 on NVD →

Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.1.2

unknown

WordPress MailChimp for WooCommerce plugin is prone to a Local File Inclusion vulnerability in 2.1.2 version. The vulnerability was in /admin/partials/tabs/notices.php file in if ( isset ( $_GET['error_notice'] ) ... IF conditional statement which lead to include(__DIR__.'/errors/'.$_GET['error_notice'].'.php'); loc...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Nov 22, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database