CVE-2026-25430: WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.2.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through <= 1.2.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25430?
CVE-2026-25430 is classified as a broken access control vulnerability that poses a significant security risk.
How do I fix CVE-2026-25430?
To fix CVE-2026-25430, update the CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin to version 1.2.3 or later.
What types of attacks can CVE-2026-25430 enable?
CVE-2026-25430 can enable unauthorized access and exploitation of sensitive information within the affected plugins.
Is CVE-2026-25430 being actively exploited?
As of now, there are no confirmed reports of active exploitation of CVE-2026-25430, but caution is advised.
Which plugins are affected by CVE-2026-25430?
CVE-2026-25430 affects versions up to 1.2.2 of the CRM Perks Integration for Mailchimp with Contact Form 7, WPForms, Elementor, and Ninja Forms.