CVE-2026-92437: Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it. The attacker can target another customer's stored abandoned-cart record using request-supplied data.
What conditions are required for exploitation?
The affected site must use a version of the Mailchimp for WooCommerce WordPress plugin earlier than 6.3 and have stored abandoned-cart records. No authentication, nonce, or ownership check is required before the affected action occurs.
What can an attacker do with a targeted record?
An attacker can modify or delete another customer's stored abandoned cart.