The MailChimp Campaigns plugin for WordPress is...
Moderate severity
Unreviewed
Published
Feb 14, 2026
to the GitHub Advisory Database
•
Updated Feb 14, 2026
Description
Published by the National Vulnerability Database
Feb 14, 2026
Published to the GitHub Advisory Database
Feb 14, 2026
Last updated
Feb 14, 2026
The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the
mailchimp_campaigns_manager_disconnect_appfunction that is hooked to the AJAX action of the same name. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the site from its MailChimp synchronization app, disrupting automated email campaigns and marketing integrations.References