CVE Identifier: CVE-2026-1303 CVSS Score: 5.3 (Medium) Description: The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the function. Authenticated attackers with Subscriber-level access and above can disconnect the site from its MailChimp synchronization app, disrupting automated email campaigns and marketing integrations. Vulnerability Type: Missing Authorization Software Type: Plugin Software Slug: olalaweb-mailchimp-campaign-manager Patched: No Remediation: No known patch available. Uninstall the affected software and find a replacement. Affected Version: <= 3.2.4 Publicly Published: February 13, 2026 Last Updated: February 14, 2026 Researcher: Nabil Irawan - Heroes Cyber Security