CVE · Low

CVE-2022-2556 — Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2556 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2 Server-Side Request Forgery (SSRF) Low 2.7 < 2.7.2 2.7.2 2022-08-03

CVE-2022-2556

The Mailchimp for WooCommerce plugin versions prior to 2.7.2 contain an AJAX function that permits administrators and other high-privileged users to initiate server-side POST requests to systems on the internal network or LAN. Because the request payload is reflected in the response, attackers with elevated permissions could leverage this capability to conduct reconnaissance and probe for vulnerable services across private networks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.