Unauthorized Data Modification in MailChimp Forms Plugin for WordPress
CVE-2026-7520

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 August 2026

What is CVE-2026-7520?

The MailChimp Forms by MailMunch plugin for WordPress is susceptible to unauthorized data alteration due to the absence of crucial capability checks in the AJAX handlers for sign_in() and sign_up(). This vulnerability affects all versions up to and including 3.2.7. Authenticated users with Subscriber-level permissions or higher can exploit this weakness to connect the site's MailMunch integration to an attacker's account by providing malicious credentials. Following this, the attacker gains access to all subscriber data gathered through the plugin's forms, effectively compromising user information and control over the forms and landing pages displayed on the site.

Affected Version(s)

Mailmunch Forms for Mailchimp 0 <= 3.2.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

t0ann9uy3n
.