Back

MEDIUM

MailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRF

Published Aug 29, 2022

Description

The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 29, 2022
Updated Aug 3, 2024
Reserved Jun 30, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Aug 29, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-34542