Impact
The Mailchimp for WooCommerce WordPress plugin versions earlier than 6.3 permit an unauthenticated user to alter or delete a customer’s abandoned cart record because the plugin does not verify authentication, CSRF protection, or ownership of the cart before processing the request. This flaw directly undermines the integrity of customer data and can result in loss of potential sales.
Affected Systems
The vulnerability affects all installations of the Mailchimp for WooCommerce plugin that run a version older than 6.3. No vendor or product name beyond the plugin itself is specified, however any WordPress site that has this plugin deployed and has the abandoned‑cart feature enabled is at risk.
Risk and Exploitability
An attacker can exploit this flaw by sending HTTP requests to the plugin’s abandoned‑cart endpoints from any network location, with no credentials required. The EPSS score is unavailable and the issue is not listed in the CISA KEV catalog, yet the success of the exploit would give the attacker full control over another customer’s cart data. Because the attack requires only basic request crafting and no prior access to the site, the risk is high and the potential impact includes revenue loss and breach of customer privacy.
OpenCVE Enrichment