CVE-2026-19699: GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
Affected Software
Event History
Frequently Asked Questions
Which users can retrieve the exposed audience metadata?
Any authenticated WordPress user with the Contributor role or a higher-privileged role can access the affected REST API endpoints.
What information is exposed?
The affected endpoints can disclose mailing-list audience metadata from the marketing account connected to the site. The provided information does not establish that subscriber records or other marketing-account data are exposed.
Which installations are affected?
GutenKit versions 2.4.12 through 2.4.15 are affected. Versions before 2.5.0 lack the required capability check on certain REST API endpoints.