SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-8151

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 is vulnerable due to a lack of CSRF checks on its settings page, enabling attackers to manipulate a logged-in administrator into altering the third-party API key. This exploitation allows attackers to redirect member registration data, including names and emails, to their own accounts, compromising user information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-8151
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
WordPress

Original NVD Description

The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is sent to the attacker-controlled account.