CVE detail
CVE-2026-15827
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are registered with permission_callback => '__return_true', and their callbacks read the site's stored Mailchimp API key from the gutenkit_settings_list option and proxy Mailchimp audience/list, merge-field, interest-category, interest-name, and subscriber-count metadata back to the caller with no login, nonce, or capability check. This makes it possible for unauthenticated attackers to retrieve private Mailchimp audience configuration information from any site that has configured the GutenKit Mailchimp integration.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 10
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7430594c-3a71-4b24-875b-014e03be868f?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3618270%40gutenkit-blocks-addon&new=3618270%40gutenkit-blocks-addonplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L62plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L43plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L17plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.6/includes/Routes/MailChimp.php#L141plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L62plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L43plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L17plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.4.11/includes/Routes/MailChimp.php#L141plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16587CVSS 4.3 · Medium
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to t…
- CVE-2026-12124CVSS 5.3 · Medium
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a…
- CVE-2026-66473CVSS 7.5 · High
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
- CVE-2026-65445CVSS 6.5 · Medium
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
- CVE-2026-65922CVSS 7.1 · High
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under sp…
- CVE-2026-66477CVSS 5.3 · Medium
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.