CVE Database /
CVE-2022-2556
CVE · Low
CVE-2022-2556 — Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2556
|
Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2 |
Server-Side Request Forgery (SSRF) |
Low
2.7
|
< 2.7.2
|
2.7.2 |
2022-08-03 |
—
|
CVE-2022-2556
The Mailchimp for WooCommerce plugin versions prior to 2.7.2 contain an AJAX function that permits administrators and other high-privileged users to initiate server-side POST requests to systems on the internal network or LAN. Because the request payload is reflected in the response, attackers with elevated permissions could leverage this capability to conduct reconnaissance and probe for vulnerable services across private networks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings