CVE-2022-2556 is a server-side request forgery (SSRF) vulnerability affecting the Mailchimp for WooCommerce WordPress plugin versions prior to 2.7.2. High-privilege users can leverage an AJAX action to send POST requests from the server to internal networks, with the response body being returned, potentially enabling internal network scanning. The vulnerability has a low CVSS score of 2.7, indicating low severity, as it requires high privileges and has a limited impact of information disclosure (C:L). The attack complexity is low, but the scope is unchanged. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.2CPE matchmatch criteria | cpe:2.3:a:mailchimp:mailchimp_for_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.