CVE-2026-92435: Schwachstellen-Eintrag (NVD)
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-30 | 2026-09-18 |
|---|---|---|
| ≥90 % | 0 | 0 |
| ≥50 % | 0 | 0 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 300 |
CVE-2026-92435 | WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress Permission Callback authorization (EUVD-2026-83517)
A vulnerability marked as critical has been reported in WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress. This issue affects some unknown processing of the component Permission Callback. The manipulation leads to missin