WordPress Plugin Vulnerabilities

Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion

Description

The plugin does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Mutantgun
Submitter
Mutantgun
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 1 day ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)

Other