CVE-2026-92435: CWE-862 Missing Authorization in Mailchimp for WooCommerce
Mailchimp for WooCommerce WordPress plugin versions before 6.1.1 have a missing authorization check in several REST API routes. This flaw allows unauthenticated users to access administrator-level endpoints and cause persistent state changes.
AI Analysis
Technical Summary
CVE-2026-92435 identifies a missing authorization vulnerability (CWE-862) in the Mailchimp for WooCommerce WordPress plugin prior to version 6.1.1. The plugin fails to verify that the requesting user has the required capabilities in the permission callback for multiple REST API routes. As a result, unauthenticated users can invoke administrator-oriented endpoints and trigger persistent changes in the plugin's state.
Potential Impact
Unauthenticated attackers can access privileged REST API endpoints intended for administrators, potentially modifying plugin settings or data persistently without proper authorization. This could lead to unauthorized configuration changes or other impacts depending on the plugin's functionality exposed via these endpoints.
Mitigation Recommendations
Upgrade the Mailchimp for WooCommerce plugin to version 6.1.1 or later, where the authorization checks have been implemented correctly. No other mitigation is indicated by the vendor advisory.
CVE-2026-92435: CWE-862 Missing Authorization in Mailchimp for WooCommerce
Description
Mailchimp for WooCommerce WordPress plugin versions before 6.1.1 have a missing authorization check in several REST API routes. This flaw allows unauthenticated users to access administrator-level endpoints and cause persistent state changes.
Affected software
Mailchimp for WooCommerce
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92435 identifies a missing authorization vulnerability (CWE-862) in the Mailchimp for WooCommerce WordPress plugin prior to version 6.1.1. The plugin fails to verify that the requesting user has the required capabilities in the permission callback for multiple REST API routes. As a result, unauthenticated users can invoke administrator-oriented endpoints and trigger persistent changes in the plugin's state.
Potential Impact
Unauthenticated attackers can access privileged REST API endpoints intended for administrators, potentially modifying plugin settings or data persistently without proper authorization. This could lead to unauthorized configuration changes or other impacts depending on the plugin's functionality exposed via these endpoints.
Mitigation Recommendations
Upgrade the Mailchimp for WooCommerce plugin to version 6.1.1 or later, where the authorization checks have been implemented correctly. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-16T10:14:50.138Z
- State
- PUBLISHED
Threat ID: 6aae2c6b55bf5e2cf5363ae8
Added to database: 09/19/2026, 06:32:11 UTC
Last enriched: 09/19/2026, 06:46:27 UTC
Last updated: 09/19/2026, 06:46:27 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.