Vulnerability Description
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2
- https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/trunk/ad
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c9d00ee8-b9df-4044-a5e
FAQ
What is CVE-2026-7520?
CVE-2026-7520 is a vulnerability with a CVSS score of 8.1 (HIGH). The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versi...
How severe is CVE-2026-7520?
CVE-2026-7520 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7520?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.