PLUGIN SECURITY

Is Mailchimp For Woocommerce safe?

Connect your store to your Mailchimp audience to track sales, create targeted emails, send abandoned cart emails, and more.

What this plugin does

  • Slug: mailchimp-for-woocommerce
  • Author: Mailchimp
  • 200000+ active installs
  • 80/100 rating (725 reviews on wordpress.org)
  • 23987221 all-time downloads
  • On WordPress.org since 2016-10-06

ecommerceemailmailchimpWorkflows

Maintenance status

  • Latest known version: 6.2
  • Last updated: 2026-08-07 5:23pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

3 known CVEs on file for Mailchimp For Woocommerce. Reported between 2017 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-73346 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 6.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 6.2 6.2 2026-08-12 ✓ fixed in latest
CVE-2022-2267 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.1 Server-Side Request Forgery (SSRF) Medium 4.3 < 2.7.1 2.7.1 2022-08-03 ✓ fixed in latest
CVE-2022-2556 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.7.2 Server-Side Request Forgery (SSRF) Low 2.7 < 2.7.2 2.7.2 2022-08-03 ✓ fixed in latest
Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.1.2 Unknown < 2.1.2 2.1.2 2017-11-22 ✓ fixed in latest

How to fix it

Keep Mailchimp For Woocommerce updated — 6.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.