WPIntell

Source evidence

Server Side Request (SSRF) vulnerability

Connect Contact Form 7 and Mailchimp · support · 2024-01-09T10:42:00+00:00

mixedsentiment
highseverity
0.95relevance
8replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

8 / 33 rows with source links

24.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

25 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
dooza resolved
My site is alerting me that the current version of this plugin has a security issue that has not been patched yet: https://patchstack.com/database/vulnerability/contact-form-7-mailchimp-extension/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-5-70-server-side-request-forgery-ssrf-vulnerability?_a_id=431 Is this plugin being updated anytime soon? Hi, Same alert for me. Some news ? Thanks Wordfence reporting it too. Sorry, I’ve swapped to an alternative on my sites. @james-feaver which one did you go for? @dooza – I went for MC4WP: Mailchimp for WordPress . It has 2+ million downloads, was last updated 7 days ago and has a 5 star rating. It also allowed me to get rid of another plugin as it can add the option to go onto the mailing list for the WooCommerce checkout. I see there is a new version for the plugin (Version 0.5.71) that came out Jan 14. Does this version fix the reported vulnerability? Can the developers please confirm? Hello, the latest update has fix any vulnerability issues. How do I download the latest version of the plugin? Plugin page says that the plugin is under review and does not allow me to download it… Hello is the plugin author OK ? They seem to have dropped off the face of the earth. I hope they are alright @rnzo can you reply to let us know? I also have an issue with the Campaign Monitor plugin – but the Author website appears to be down for some weeks now… https://wordpress.org/support/topic/dev-website-help-is-dead-link-is-this-plugin-still-alive/

Comments

8 shown
jumpinsteph 2024-01-12T09:14:00+00:00

Hi, Same alert for me. Some news ? Thanks

James 2024-01-15T19:02:00+00:00

Wordfence reporting it too. Sorry, I’ve swapped to an alternative on my sites.

dooza 2024-01-15T19:29:00+00:00

@james-feaver which one did you go for?

James 2024-01-15T19:48:00+00:00

@dooza – I went for MC4WP: Mailchimp for WordPress . It has 2+ million downloads, was last updated 7 days ago and has a 5 star rating. It also allowed me to get rid of another plugin as it can add the option to go onto the mailing list for the WooCommerce checkout.

mmazziotti 2024-01-17T16:06:00+00:00

I see there is a new version for the plugin (Version 0.5.71) that came out Jan 14. Does this version fix the reported vulnerability? Can the developers please confirm?

Renzo Johnson 2024-01-19T17:08:00+00:00

Hello, the latest update has fix any vulnerability issues.

trajektorijus 2024-01-25T08:18:00+00:00

How do I download the latest version of the plugin? Plugin page says that the plugin is under review and does not allow me to download it…

Iamhere 2024-05-18T06:57:00+00:00

Hello is the plugin author OK ? They seem to have dropped off the face of the earth. I hope they are alright @rnzo can you reply to let us know? I also have an issue with the Campaign Monitor plugin – but the Author website appears to be down for some weeks now… https://wordpress.org/support/topic/dev-website-help-is-dead-link-is-this-plugin-still-alive/