plugin

Mailchimp Forms By Mailmunch Vulnerabilities

11 known security issues reported for the Mailchimp Forms By Mailmunch WordPress plugin. Most recent disclosed Aug 4, 2026.

1 high 5 medium

Running Mailchimp Forms By Mailmunch on your site? Check whether your installed version is affected.

Scan your site free

MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action

high

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and ab...

CVSS:
8.1
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Aug 4, 2026

CVE-2026-7520 on NVD →

MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.1.5

unknown

[en] Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Dec 13, 2024

CVE-2023-40203 on NVD →

MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.4

unknown

[en] The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Nov 20, 2024

CVE-2024-8726 on NVD →

MailChimp Forms by MailMunch <= 3.2.3 - Reflected Cross-Site Scripting

medium

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Nov 19, 2024

CVE-2024-8726 on NVD →

MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Apr 15, 2024

CVE-2024-31378 on NVD →

MailChimp Forms by MailMunch <= 3.2.1 - Cross-Site Request Forgery

medium

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the integrate case. This makes it possible for unauthenticated attackers to update the plugin's access token via a forged req...

CVSS:
4.3
Affected:
up to 3.2.1
Fixed in:
3.2.2
Disclosed:
Apr 10, 2024

CVE-2024-31378 on NVD →

MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.2.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailChimp Forms by MailMunch allows Stored XSS.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.2.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Mar 27, 2024

CVE-2024-29793 on NVD →

MailChimp Forms by MailMunch <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
Mar 25, 2024

CVE-2024-29793 on NVD →

MailChimp Forms by MailMunch [mailchimp-forms-by-mailmunch] < 3.1.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions.

Affected:
up to 3.1.8
Fixed in:
3.1.8
Disclosed:
Oct 16, 2023

CVE-2023-45748 on NVD →

MailChimp Forms by MailMunch <= 3.1.7 - Cross-Site Request Forgery via Multiple AJAX actions

medium

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.7. This is due to missing nonce validation on several of the plugin's functions, such as delete_email(), delete_widget(), change_email_status(), and settings_page(). This makes it poss...

CVSS:
5.4
Affected:
up to 3.1.7
Fixed in:
3.1.8
Disclosed:
Oct 12, 2023

CVE-2023-45748 on NVD →

MailChimp Forms by MailMunch <= 3.1.4 - Missing Authorization via multiple AJAX actions

medium

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'delete_widget', 'change_email_status', and 'delete_email' AJAX functions in versions up to, and including, 3.1.4. This makes it possible for authenticated a...

CVSS:
5.4
Affected:
up to 3.1.4
Fixed in:
3.1.5
Disclosed:
Aug 11, 2023

CVE-2023-40203 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database