Conversation
supportHi there, Are you aware of this vulnerability: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability The current version is being flagged as still having an issue.
Hi @dooza , Thank you for bringing this to our attention! Yes, we are aware of this vulnerability (CVE-2025-68989) and it was addressed in version 0.9.68 . If you’re using version 0.9.68 or later, you are protected.
Hi Renzo, Thank for the update, I have applied it to all the sites I have that use it, sadly Patchstack thinks your latest version is still vulnerable: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability
Version 0.9.69 should be good, let us know if you have other finding: https://chimpmatic.com/contact
Hi Renzo, The Patchstack page is now saying 0.9.69 and lower is vulnerable. Are you in contact with them about the issue? The link I posted before has a way to claim ownership as the developer of the plugin, it might help you get to the root of what they think the issue is.
Hi @rnzo , the latest version seems to be good now, no more warnings after updating to it. Thank you for your help with this!
Hi @dooza , Thank you for bringing this to our attention! Yes, we are aware of this vulnerability (CVE-2025-68989) and it was addressed in version 0.9.68 . If you’re using version 0.9.68 or later, you are protected.
Hi Renzo, Thank for the update, I have applied it to all the sites I have that use it, sadly Patchstack thinks your latest version is still vulnerable: https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability
Version 0.9.69 should be good, let us know if you have other finding: https://chimpmatic.com/contact
Hi Renzo, The Patchstack page is now saying 0.9.69 and lower is vulnerable. Are you in contact with them about the issue? The link I posted before has a way to claim ownership as the developer of the plugin, it might help you get to the root of what they think the issue is.
Hi @rnzo , the latest version seems to be good now, no more warnings after updating to it. Thank you for your help with this!