Unauthorized Data Modification in MailChimp Forms Plugin for WordPress
CVE-2026-7520
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-7520?
The MailChimp Forms by MailMunch plugin for WordPress is susceptible to unauthorized data alteration due to the absence of crucial capability checks in the AJAX handlers for sign_in() and sign_up(). This vulnerability affects all versions up to and including 3.2.7. Authenticated users with Subscriber-level permissions or higher can exploit this weakness to connect the site's MailMunch integration to an attacker's account by providing malicious credentials. Following this, the attacker gains access to all subscriber data gathered through the plugin's forms, effectively compromising user information and control over the forms and landing pages displayed on the site.
Affected Version(s)
Mailmunch Forms for Mailchimp 0 <= 3.2.7