PT-2026-8072 · WordPress · Mailchimp Campaigns

Nabil Irawan

·

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2026-1303

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MailChimp Campaigns plugin for WordPress versions through 3.2.4
Description The MailChimp Campaigns plugin for WordPress is affected by a missing authorization issue. Specifically, the mailchimp campaigns manager disconnect app function lacks proper capability checks when handling the AJAX action with the same name. This allows authenticated attackers with Subscriber-level access or higher to disconnect the WordPress site from its MailChimp synchronization application, potentially disrupting email campaigns and marketing integrations.
Recommendations Update MailChimp Campaigns plugin for WordPress to a version later than 3.2.4.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1303

Affected Products

Mailchimp Campaigns