Description
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Modification of Customer Abandoned Cart Records
Action: Patch Now
AI Analysis

Impact

The Mailchimp for WooCommerce WordPress plugin versions earlier than 6.3 permit an unauthenticated user to alter or delete a customer’s abandoned cart record because the plugin does not verify authentication, CSRF protection, or ownership of the cart before processing the request. This flaw directly undermines the integrity of customer data and can result in loss of potential sales.

Affected Systems

The vulnerability affects all installations of the Mailchimp for WooCommerce plugin that run a version older than 6.3. No vendor or product name beyond the plugin itself is specified, however any WordPress site that has this plugin deployed and has the abandoned‑cart feature enabled is at risk.

Risk and Exploitability

An attacker can exploit this flaw by sending HTTP requests to the plugin’s abandoned‑cart endpoints from any network location, with no credentials required. The EPSS score is unavailable and the issue is not listed in the CISA KEV catalog, yet the success of the exploit would give the attacker full control over another customer’s cart data. Because the attack requires only basic request crafting and no prior access to the site, the risk is high and the potential impact includes revenue loss and breach of customer privacy.

Generated by OpenCVE AI on October 3, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Mailchimp for WooCommerce to version 6.3 or later.
  • If an immediate update is not possible, restrict the abandoned‑cart modification and deletion endpoints to authenticated users with appropriate privileges, or add custom access‑control logic to verify cart ownership before processing requests.
  • Audit any custom integrations or code that interacts with abandoned carts to ensure proper authentication and ownership checks are in place, and remove or harden any functions that allow unauthenticated modifications.

Generated by OpenCVE AI on October 3, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
Title Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:21.291Z

Reserved: 2026-09-16T10:16:38.474Z

Link: CVE-2026-92437

cve-icon Vulnrichment

Updated: 2026-10-03T15:00:33.479Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:46.207

Modified: 2026-10-03T16:16:42.700

Link: CVE-2026-92437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses