UNKNOWN NVD

CVE-2026-92435

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback fo

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.

References

Published: 2026-09-19 · Source: NVD · Feed updated: 2026-09-19
This unknown severity vulnerability was published on 2026-09-19 via NVD.
vulnfeed aggregates 14156 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.