CyberRota Analysis
AI-GeneratedThe Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 is vulnerable due to a lack of CSRF checks on its settings page, enabling attackers to manipulate a logged-in administrator into altering the third-party API key. This exploitation allows attackers to redirect member registration data, including names and emails, to their own accounts, compromising user information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is sent to the attacker-controlled account.