CVE-2026-92437 PUBLISHED

Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion

Assigner: WPScan
Reserved: 16.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.

Product Status

Vendor Unknown
Product Mailchimp for WooCommerce
Versions Default: unaffected
  • affected from 0 to 6.3 (excl.)

Credits

  • Mutantgun finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE