CVE-2026-8151
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 02, 2026
Vendor
unknown
Description
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is sent to the attacker-controlled account.