WordPress Plugin Vulnerabilities
Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion
Description
The plugin does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mutantgun
Submitter
Mutantgun
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-01 (about 1 day ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)