CVE · Medium

CVE-2022-2267 — Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2267 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.1 Server-Side Request Forgery (SSRF) Medium 4.3 < 2.7.1 2.7.1 2022-08-03

CVE-2022-2267

The Mailchimp for WooCommerce plugin versions prior to 2.7.1 contains an AJAX endpoint that enables authenticated users with minimal privileges to execute server-side POST requests targeting internal network resources. This vulnerability allows attackers to conduct reconnaissance on private networks by sending arbitrary requests and observing the responses, effectively bypassing network segmentation protections.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.