CVE-2026-92437
Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
| Vendor | unknown |
| Product | mailchimp for woocommerce |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mailchimp for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown mailchimp for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Mailchimp for WooCommerce
0 < 6.3
References
Credits
Mutantgun WPScan