CVE-2026-15827

GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are registered with permission_callback => '__return_true', and their callbacks read the site's stored Mailchimp API key from the gutenkit_settings_list option and proxy Mailchimp audience/list, merge-field, interest-category, interest-name, and subscriber-count metadata back to the caller with no login, nonce, or capability check. This makes it possible for unauthenticated attackers to retrieve private Mailchimp audience configuration information from any site that has configured the GutenKit Mailchimp integration.


We have discovered 313 live websites that are affected by CVE-2026-15827.

Run a Free Instant Scan




Affected Software

Product  Gutenkit Blocks Addon
Category Wordpress Plugins
Vulnerable Domains313 live websites (100% of Gutenkit Blocks Addon install base)
Vulnerable Versions
  • from 0 through 2.4.12
Vulnerable Versions Count29 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Viet Anh Ngo (finder)

Website Distribution by Country

Number of websites using CVE-2026-15827
United States96 websites



Germany37 websites
India28 websites
France14 websites
Cyprus12 websites
Brazil11 websites
GB10 websites
Spain8 websites
Italy7 websites
Russia6 websites

Website Distribution by TLD

Number of websites using CVE-2026-15827
.com140 websites
.org26 websites
.de20 websites
.net13 websites
.fr10 websites
.com.br7 websites
.ca4 websites
.it4 websites
.com.au4 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15827

Top websites that are affected by CVE-2026-15827. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.***.br Brazil***,***
*********.*****.**.us United States***,***
*******.com Germany***,***
***********.com United States***,***
***************.ca Canada***,***
*****.com United States***,***
*******.**.tz GB***,***
*****.fr France***,***
*********************.ca Canada*,***,***
**********.info Cyprus*,***,***
See full domain list

FAQ

CVE-2026-15827 is Missing Authorization in Gutenkit Blocks Addon
A total of 313 websites have been identified as vulnerable to CVE-2026-15827, based on global website indexing conducted by WebTechSurvey.
The Gutenkit Blocks Addon is affected by the CVE-2026-15827 vulnerability.
Gutenkit Blocks Addon versions up to and including 2.4.12 are vulnerable to CVE-2026-15827.

References