
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1781 is a Missing Authorization vulnerability in the MC4WP: Mailchimp for WordPress plugin that allows unauthenticated attackers to arbitrarily unsubscribe any email address from a connected Mailchimp audience. The flaw affects all versions of the plugin up to and including 4.11.1. It was published on March 11, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, ENISA EUVD).
The root cause is CWE-862 (Missing Authorization): the plugin's form listener trusts the _mc4wp_action POST parameter without any server-side validation or authorization check, allowing it to be set to unsubscribe by any unauthenticated user (Wordfence). The form ID required to target a specific form is publicly exposed in the HTML source of any page hosting the form, making reconnaissance trivial. The vulnerable logic resided in includes/forms/class-form-listener.php (around line 207) and includes/forms/class-form.php, where the process_unsubscribe_form() method was invoked without verifying the requester's identity or intent (GitHub Commit). No authentication or special privileges are required; only network access to the target WordPress site is needed.
Successful exploitation allows an unauthenticated attacker to remove arbitrary email addresses from the site's connected Mailchimp audience lists, causing integrity and availability impacts to the site's email marketing data. This could result in mass unsubscription of legitimate subscribers, disrupting email campaigns and causing potential business and reputational harm. There is no confidentiality impact (no data is exposed), and the attack does not enable code execution or lateral movement within the hosting environment (ENISA EUVD, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward to exploit for any attacker who can identify a vulnerable site.
EMAIL) and setting _mc4wp_action=unsubscribe along with the obtained form ID.curl or a browser's developer tools). The plugin processes the request without authorization checks and triggers the unsubscribe action against the specified email address in the connected Mailchimp audience._mc4wp_action=unsubscribe parameter from unexpected or automated IP addresses._mc4wp_action=unsubscribe in the request body; plugin log entries (if enabled) showing messages such as Form [ID] > Successfully unsubscribed [email] for multiple addresses in a short timeframe.The vendor (ibericode) addressed this vulnerability in version 4.11.2 by removing the ability to unsubscribe through a form entirely — the process_unsubscribe_form() method now returns an error and logs a deprecation warning instead of processing the action (GitHub Commit). Site administrators should update the MC4WP: Mailchimp for WordPress plugin to version 4.11.2 or later immediately via the WordPress plugin dashboard. As a temporary workaround prior to patching, administrators can disable or remove any forms that include the _mc4wp_action field with an unsubscribe option, or use a web application firewall (WAF) rule to block POST requests containing _mc4wp_action=unsubscribe.
Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report for March 9–15, 2026 (Wordfence Blog). Sucuri also included it in their March 2026 vulnerability patch roundup (Sucuri Blog). Community reaction has been relatively muted given the medium severity rating and limited exploitation potential beyond subscriber list disruption.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."