WordPress Mailchimp for WooCommerce plugin <= 2.7.1 - Authenticated Server-Side Request Forgery (SSRF) vulnerability
PSID
c951eb30995d
Classification
Server Side Request Forgery (SSRF)
OWASP Top 10
A1: Injection
Required privilege
Requires high role user authentication like admin.
Publicly disclosed
2022-08-03
Patchstack vPatch available since
09.12.2021
Details
Authenticated Server-Side Request Forgery (SSRF) vulnerability discovered by Miguel Xavier Penha Neto in WordPress Mailchimp for WooCommerce plugin (versions <= 2.7.1).
Solution
Update the WordPress MailChimp For WooCommerce plugin to the latest available version (at least 2.7.2).
References
Vulnerability details