CVE-2026-92435
Last modified
CVE-2026-92435 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Mailchimp for WooCommerce | < 6.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-92435?
How severe is CVE-2026-92435?
How do I fix CVE-2026-92435?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92421The Hydra Booking — Appointment Scheduling & Booking Calenda…4.7
- CVE-2026-92422The Meow Gallery WordPress plugin before 5.5.5 does not prop…6.5
- CVE-2026-92423The Meow Gallery WordPress plugin before 5.5.5 does not perf…2.7
- CVE-2026-92425The Hydra Booking — Appointment Scheduling & Booking Calenda…5.5
- CVE-2026-9243The Plus Addons for Elementor plugin for WordPress is vulner…6.4
- CVE-2026-92430The Rede Itaú for WooCommerce — Payment PIX, Credit Card and…5.3
- CVE-2026-9244Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-9245Improper input validation in the external authentication pro…5
- CVE-2026-92455yshop-crm through 2.1.3 fails to enforce authorization on th…4.3
- CVE-2026-92456yshop-crm through 2.1.3 fails to enforce authorization on th…7.1
- CVE-2026-92457yshop-crm through 2.1.3 contains a missing authorization vul…6.5
- CVE-2026-92458yshop-crm through 2.1.3 contains a missing authorization vul…4.3
Are you affected by CVE-2026-92435?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
