Skip to main content

Threat intelligence

Contact Form 7 Extension For Mailchimp <= 0.9.54 - Authenticated (Contributor+) Information Exposure

CVE-2025-68989 · contact-form-7-mailchimp-extension

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Contact Form 7 Mailchimp Extension at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Contact Form 7 Extension For Mailchimp <= 0.9.54 - Authenticated (Contributor+) Information Exposure
Affected software
contact-form-7-mailchimp-extension(Plugin)
Affected versions
  • ≤ 0.9.54
Authentication
Authenticated (see advisory title)
Vulnerability type
Other
Published
21 December 2025
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 8ca1bf69-bc71-4137-a908-58c1915f654a). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Contact Form 7 Mailchimp Extension version against this catalog when the Defence plugin is connected to your WordPress site.