Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
Summary
| CVE | CVE-2026-92435 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-19 07:16:34 UTC |
| Updated | 2026-09-19 07:16:34 UTC |
| Description | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. |
Risk And Classification
Problem Types: CWE-862 Missing Authorization
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Mailchimp For WooCommerce | affected 6.1.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/4b3f9c83-8986-40d9-ab1a-848550ea7882 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Pablo González and Francisco José Ramírez (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.