Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Mailchimp for WooCommercepublic PoCs found — 1
cve_referencewpscan.com/vulnerability/4b3f9c83-8986-40d9-ab1a-848550ea7882/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.