MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action
high
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- CVSS:
- 8.1
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- Aug 4, 2026
CVE-2026-7520 on NVD →
MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.1.5
unknown
[en] Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Dec 13, 2024
CVE-2023-40203 on NVD →
MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.4
unknown
[en] The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.4
- Disclosed:
- Nov 20, 2024
CVE-2024-8726 on NVD →
MailChimp Forms by MailMunch <= 3.2.3 - Reflected Cross-Site Scripting
medium
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.4
- Disclosed:
- Nov 19, 2024
CVE-2024-8726 on NVD →
MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Apr 15, 2024
CVE-2024-31378 on NVD →
MailChimp Forms by MailMunch <= 3.2.1 - Cross-Site Request Forgery
medium
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the integrate case. This makes it possible for unauthenticated attackers to update the plugin's access token via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.2
- Disclosed:
- Apr 10, 2024
CVE-2024-31378 on NVD →
MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailChimp Forms by MailMunch allows Stored XSS.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.2.
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.3
- Disclosed:
- Mar 27, 2024
CVE-2024-29793 on NVD →
MailChimp Forms by MailMunch <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.3
- Disclosed:
- Mar 25, 2024
CVE-2024-29793 on NVD →
MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.1.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions.
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.8
- Disclosed:
- Oct 16, 2023
CVE-2023-45748 on NVD →
MailChimp Forms by MailMunch <= 3.1.7 - Cross-Site Request Forgery via Multiple AJAX actions
medium
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.7. This is due to missing nonce validation on several of the plugin's functions, such as delete_email(), delete_widget(), change_email_status(), and settings_page(). This makes it poss...
- CVSS:
- 5.4
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.8
- Disclosed:
- Oct 12, 2023
CVE-2023-45748 on NVD →
MailChimp Forms by MailMunch <= 3.1.4 - Missing Authorization via multiple AJAX actions
medium
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'delete_widget', 'change_email_status', and 'delete_email' AJAX functions in versions up to, and including, 3.1.4. This makes it possible for authenticated a...
- CVSS:
- 5.4
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Aug 11, 2023
CVE-2023-40203 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database