CVE-2026-92435: Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API
Published Sep 19, 2026
·Updated
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Affected Software
1 affected component
Mailchimp Mailchimp for WooCommerce<6.1.1
Event History
Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit the affected REST API routes?
Unauthenticated users can reach several administrator-oriented REST API routes because the plugin does not verify the required capability in their permission callback.
2
What impact can exploitation have?
An unauthenticated attacker can trigger a persistent state change through the affected REST API endpoints.
3
Which installations are affected?
Mailchimp for WooCommerce versions earlier than 6.1.1 are affected.