---
id: CVE-2026-92435
title: >-
  The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify
  that the requesting user holds the required capability in the permission
  callback for several of its REST API routes, allowing unauthenticated users to
  reach adm…
summary: >-
  The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify
  that the requesting user holds the required capability in the permission
  callback for several of its REST API routes, allowing unauthenticated users to
  reach adm…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Mailchimp for WooCommerce
affected:
  - mailchimp_for_woocommerce < 6.1.1
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92435'
references:
  - url: 'https://wpscan.com/vulnerability/4b3f9c83-8986-40d9-ab1a-848550ea7882/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00304
epssPercentile: 0.20518
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-19T13:10:15.932912Z'
ingestedAt: '2026-09-19T06:59:13.111Z'
---

## Overview

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
