Lack of CSRF Protection in Simple Membership MailChimp Integration Plugin by WordPress
CVE-2026-8151
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-8151?
The Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 lacks essential CSRF checks on its settings page. This deficiency allows attackers to exploit the vulnerability by tricking a logged-in administrator into altering the third-party API key. If successful, the attacker would reroute member registration data, including names, emails, and membership levels, to a malicious account controlled by the attacker. Thus, sensitive user information could be compromised, exposing both users and administrators to significant risks.
Affected Version(s)
Simple Membership MailChimp Integration 0 < 1.9.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved