WPIntell

Source evidence

Security Vulnerability

Connect Contact Form 7 and Mailchimp · support · 2026-01-02T16:23:00+00:00

neutralsentiment
highseverity
0.69relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

8 / 33 rows with source links

24.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

25 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
dooza resolved
Hi there, Are you aware of this vulnerability: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability The current version is being flagged as still having an issue. Hi @dooza , Thank you for bringing this to our attention! Yes, we are aware of this vulnerability (CVE-2025-68989) and it was addressed in version 0.9.68 . If you’re using version 0.9.68 or later, you are protected. Hi Renzo, Thank for the update, I have applied it to all the sites I have that use it, sadly Patchstack thinks your latest version is still vulnerable: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability Version 0.9.69 should be good, let us know if you have other finding: https://chimpmatic.com/contact Hi Renzo, The Patchstack page is now saying 0.9.69 and lower is vulnerable. Are you in contact with them about the issue? The link I posted before has a way to claim ownership as the developer of the plugin, it might help you get to the root of what they think the issue is. Hi @rnzo , the latest version seems to be good now, no more warnings after updating to it. Thank you for your help with this!

Comments

5 shown
Renzo Johnson 2026-01-06T02:00:00+00:00

Hi @dooza , Thank you for bringing this to our attention! Yes, we are aware of this vulnerability (CVE-2025-68989) and it was addressed in version 0.9.68 . If you’re using version 0.9.68 or later, you are protected.

dooza 2026-01-06T10:27:00+00:00

Hi Renzo, Thank for the update, I have applied it to all the sites I have that use it, sadly Patchstack thinks your latest version is still vulnerable: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability

Renzo Johnson 2026-01-07T21:36:00+00:00

Version 0.9.69 should be good, let us know if you have other finding: https://chimpmatic.com/contact

dooza 2026-01-08T16:15:00+00:00

Hi Renzo, The Patchstack page is now saying 0.9.69 and lower is vulnerable. Are you in contact with them about the issue? The link I posted before has a way to claim ownership as the developer of the plugin, it might help you get to the root of what they think the issue is.

dooza 2026-01-15T11:01:00+00:00

Hi @rnzo , the latest version seems to be good now, no more warnings after updating to it. Thank you for your help with this!