Blind Server-Side Request Forgery in Block For Mailchimp Plugin for WordPress
CVE-2025-10735
4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2025
What is CVE-2025-10735?
The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress allows unauthenticated attackers to initiate Blind Server-Side Request Forgery (SSRF) attacks. This vulnerability exists in all versions up to and including 1.1.12, specifically via the mcbSubmit_Form_Data() function. Attackers could exploit this flaw to send HTTP requests to arbitrary internal services, potentially exposing sensitive information or altering data.
Affected Version(s)
Block For Mailchimp – Easy Mailchimp Form Integration * <= 1.1.12