CVE-2024-30523 MEDIUM

CVE-2024-30523: WordPress Paid Memberships Pro – Mailchimp Add On plugin <= 2.3.4 - Sensitive Data Exposure vulnerability

Vendor Paid Memberships Pro
Product Paid Memberships Pro – Mailchimp Add On
Weakness CWE-532 · Sensitive info in logs
Published March 31, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This issue affects Paid Memberships Pro – Mailchimp Add On: from n/a through 2.3.4.

Explanation of Vulnerability in Simple Terms

02Summary

The Mailchimp Add-On for Paid Memberships Pro exposes sensitive information through improper logging or data handling. An attacker on the network can read low-sensitivity data without authentication. The vulnerability affects versions up to 2.3.4. Update to a version newer than 2.3.4 to remediate.

What an attacker can do

03Attacker Capabilities

Read sensitive data transmitted between the plugin and Mailchimp without authentication.

Potential impact on your site

04Site Impact

Member data or API credentials may be exposed to unauthenticated network observers.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

March 31, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE