CVE-2022-2267: MailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRF
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2267?
CVE-2022-2267 has been assigned a severity level that indicates a significant risk due to improper access controls.
How do I fix CVE-2022-2267?
To fix CVE-2022-2267, update the Mailchimp for WooCommerce plugin to version 2.7.1 or later.
Who is affected by CVE-2022-2267?
CVE-2022-2267 affects any website using the Mailchimp for WooCommerce plugin versions prior to 2.7.1.
What kind of vulnerability is CVE-2022-2267?
CVE-2022-2267 is an integrity vulnerability that allows logged-in users to make unauthorized POST requests via AJAX.
What could an attacker achieve with CVE-2022-2267?
An attacker exploiting CVE-2022-2267 could potentially send requests to the server on behalf of legitimate users, revealing sensitive data.