CVE-2026-1781

MC4WP: Mailchimp for WordPress <= 4.11.1 - Missing Authorization to Unauthenticated Arbitrary Subscription Deletion

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.11.1. This is due to the plugin trusting the `_mc4wp_action` POST parameter without validation, allowing unauthenticated attackers to force the form to process unsubscribe actions instead of subscribe actions. This makes it possible for unauthenticated attackers to arbitrarily unsubscribe any email address from the connected Mailchimp audience via the `_mc4wp_action` parameter, granted they can obtain the form ID (which is publicly exposed in the HTML source).


We have discovered 83,538 live websites that are affected by CVE-2026-1781.

Run a Free Instant Scan




Affected Software

Product  MailChimp for WordPress
Category Marketing Automation
Vulnerable Domains83,538 live websites (53% of MailChimp for WordPress install base)
Vulnerable Versions
  • from 0 through 4.11.1
Vulnerable Versions Count123 versions ( 92% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Mar 11, 2026
  • Updated - Apr 8, 2026

Credits

  • Sarawut Poolkhet (finder)

Website Distribution by Country

Number of websites using CVE-2026-1781
United States26,649 websites



Germany6,664 websites
GB5,651 websites
Italy4,738 websites
France4,358 websites
Netherlands2,403 websites
Spain2,304 websites
Canada2,040 websites
Australia1,794 websites
India1,549 websites

Website Distribution by TLD

Number of websites using CVE-2026-1781
.com38,310 websites
.org4,816 websites
.co.uk3,528 websites
.it3,191 websites
.de2,794 websites
.nl1,909 websites
.net1,652 websites
.com.au1,512 websites
.fr1,459 websites
.com.br1,339 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1781

Top websites that are affected by CVE-2026-1781. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
****.org United States*,***
******.com United States*,***
********.com GB*,***
***************.***.au Australia**,***
*******.com United States**,***
******.com United States**,***
*********.com Switzerland**,***
***.me United States**,***
***********.com GB**,***
See full domain list

FAQ

CVE-2026-1781 is Missing Authorization in MailChimp for WordPress
A total of 83,538 websites have been identified as vulnerable to CVE-2026-1781, based on global website indexing conducted by WebTechSurvey.
The MailChimp for WordPress is affected by the CVE-2026-1781 vulnerability.
MailChimp for WordPress versions up to and including 4.11.1 are vulnerable to CVE-2026-1781.

References