Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-8151

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Sep 02, 2026
Vendor unknown

Description

The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is sent to the attacker-controlled account.

References