High severity8.1NVD Advisory· Published Aug 5, 2026· Updated Aug 12, 2026
CVE-2026-7520
CVE-2026-7520
Description
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sign_in() and sign_up() AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=3.2.7+ 1 more
- (no CPE)range: <=3.2.7
- (no CPE)range: <=3.2.7
Patches
Vulnerability mechanics
References
8- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.phpnvd
- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.phpnvd
- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailchimp-mailmunch.phpnvd
- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.phpnvd
- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.phpnvd
- plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/trunk/admin/class-mailchimp-mailmunch-admin.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/c9d00ee8-b9df-4044-a5e2-320391d6c9b1nvd
News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026