CVE-2026-7520 Details
Description
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
A vulnerability exists in the MailChimp Forms by MailMunch plugin for WordPress, specifically in versions through 3.2.7. The issue arises from a lack of proper capability checks in the 'sign_in()' and 'sign_up()' AJAX handlers. This flaw allows authenticated attackers with Subscriber-level access or higher to manipulate the site's MailMunch integration. By providing their own credentials, these attackers can link the integration to an account they control. Once this connection is established, any subscriber data collected through the plugin's forms is sent to the attacker, and the forms or landing pages displayed on the site are sourced from the attacker's MailMunch account.
Users are advised to update the MailChimp Forms by MailMunch plugin to version 3.2.8 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MailMunch MailChimp Forms by MailMunch | <= 3.2.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion