rootpwn

medium · CVSS v3 5.3 · EPSS 0.00177

CVE-2026-92437

The Mailchimp for WooCommerce WordPress plugin (v<6.3) fails to enforce authentication and ownership checks on abandoned‑cart records, allow

Overview

The Mailchimp for WooCommerce WordPress plugin (v<6.3) fails to enforce authentication and ownership checks on abandoned‑cart records, allowing an unauthenticated attacker to modify or delete another customer’s cart data. This flaw can lead to data loss or manipulation of abandoned‑cart marketing efforts.

Description

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.

Impact

Confidentiality: customer cart data may be altered or erased, affecting marketing insights. Integrity: abandoned‑cart records can be tampered with, leading to inaccurate reporting. Availability: deletion of carts may disrupt customer recovery flows. Defenders: site administrators and WordPress security teams.

Remediation

Upgrade the Mailchimp for WooCommerce plugin to version 6.3 or later. If upgrade is not immediately possible, restrict the plugin’s endpoints to authenticated users only, or disable the abandoned‑cart feature until patched. Monitor abandoned‑cart logs for unexpected deletions or modifications. Apply any vendor‑issued security patches promptly.

Risk context

The CVSS v3 score of 5.3 indicates medium risk, and the EPSS of 0.00177 suggests a low likelihood of exploitation. Nonetheless, the vulnerability can affect customer data integrity, so timely patching is advisable.

Affected products

  • Mailchimp for WooCommerce
  • WooCommerce

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
—
EPSS
0.00177

WordPress plugin abandoned-cart authentication data-modification Mailchimp WooCommerce

← All CVEs