The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mailmunch
Mailmunch mailmunch Forms For Mailchimp Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mailmunch
Mailmunch mailmunch Forms For Mailchimp Wordpress Wordpress wordpress |
Wed, 05 Aug 2026 08:15:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-08-05T07:39:23.697Z
Updated: 2026-08-05T13:11:29.519Z
Reserved: 2026-04-30T16:42:06.998Z
Link: CVE-2026-7520
Updated: 2026-08-05T13:11:22.472Z
No data.
No data.