Title: Security Vulnerability
Last modified: January 2, 2026

---

# Security Vulnerability

 *  Resolved [dooza](https://wordpress.org/support/users/dooza/)
 * (@dooza)
 * [6 months, 2 weeks ago](https://wordpress.org/support/topic/security-vulnerability-208/)
 * Hi there,
 * Are you aware of this vulnerability: [https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability](https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability)
 * The current version is being flagged as still having an issue.

Viewing 5 replies - 1 through 5 (of 5 total)

 *  Plugin Author [Renzo Johnson](https://wordpress.org/support/users/rnzo/)
 * (@rnzo)
 * [6 months, 2 weeks ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18775715)
 * Hi [@dooza](https://wordpress.org/support/users/dooza/),
 * Thank you for bringing this to our attention! Yes, we are aware of this vulnerability(
   CVE-2025-68989) and it was **addressed in version 0.9.68**. 
   If you’re using 
   version 0.9.68 or later, you are protected. 
 *  Thread Starter [dooza](https://wordpress.org/support/users/dooza/)
 * (@dooza)
 * [6 months, 2 weeks ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18776110)
 * Hi Renzo,
 * Thank for the update, I have applied it to all the sites I have that use it, 
   sadly Patchstack thinks your latest version is still vulnerable: [https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability](https://patchstack.com/database/wordpress/plugin/contact-form-7-mailchimp-extension/vulnerability/wordpress-contact-form-7-extension-for-mailchimp-plugin-0-9-49-sensitive-data-exposure-vulnerability)
 *  Plugin Author [Renzo Johnson](https://wordpress.org/support/users/rnzo/)
 * (@rnzo)
 * [6 months, 2 weeks ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18778309)
 * Version **0.9.69** should be good, let us know if you have other finding: [https://chimpmatic.com/contact](https://chimpmatic.com/contact)
 *  Thread Starter [dooza](https://wordpress.org/support/users/dooza/)
 * (@dooza)
 * [6 months, 1 week ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18779347)
 * Hi Renzo,
 * The Patchstack page is now saying 0.9.69 and lower is vulnerable. Are you in 
   contact with them about the issue? The link I posted before has a way to claim
   ownership as the developer of the plugin, it might help you get to the root of
   what they think the issue is.
 *  Thread Starter [dooza](https://wordpress.org/support/users/dooza/)
 * (@dooza)
 * [6 months ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18786893)
 * Hi [@rnzo](https://wordpress.org/support/users/rnzo/), the latest version seems
   to be good now, no more warnings after updating to it. Thank you for your help
   with this!

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Security Vulnerability’ is closed to new replies.

 * ![](https://ps.w.org/contact-form-7-mailchimp-extension/assets/icon.svg?rev=3605002)
 * [Connect Contact Form 7 to Mailchimp, Brevo, MailerLite & Klaviyo](https://wordpress.org/plugins/contact-form-7-mailchimp-extension/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/contact-form-7-mailchimp-extension/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/contact-form-7-mailchimp-extension/)
 * [Active Topics](https://wordpress.org/support/plugin/contact-form-7-mailchimp-extension/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/contact-form-7-mailchimp-extension/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/contact-form-7-mailchimp-extension/reviews/)

## Tags

 * [chimpmatic](https://wordpress.org/support/topic-tag/chimpmatic/)

 * 7 replies
 * 2 participants
 * Last reply from: [dooza](https://wordpress.org/support/users/dooza/)
 * Last activity: [6 months ago](https://wordpress.org/support/topic/security-vulnerability-208/#post-18786893)
 * Status: resolved