Sceawere
Vulnerability Detail
CVE-2026-92437UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mailchimp WooCommerce Unauthenticated Data Manipulation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- Mailchimp for WooCommerce
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-03T06:16:46.207Z",
"pubdate": "2026-10-03T06:16:46.207Z",
"executiveSummary": "The Mailchimp for WooCommerce WordPress plugin, in versions prior to 6.3, contains a critical security flaw involving improper authorization validation. This vulnerability allows an unauthenticated remote attacker to manipulate or delete arbitrary customer abandoned-cart records within the WooCommerce database.\nThe root cause of this vulnerability is the failure to implement essential security mechanisms, such as authentication checks, nonce verification, or ownership validation, when processing requests related to cart data management.\nThe impact of this vulnerability includes unauthorized data modification and potential service disruption for legitimate users, as attackers can programmatically target specific cart identifiers. Given that the vulnerability does not require any level of authentication, it presents a significant risk to data integrity and customer privacy for affected WordPress installations.\nThis flaw is exploitable over a network without requiring prior access to the system. By injecting maliciously crafted requests, an attacker can bypass the intended access controls, successfully interacting with cart data that should otherwise be protected. Immediate remediation through version upgrading is required to eliminate the exposure.",
"technicalDetails": "The vulnerability resides within the request handling logic of the Mailchimp for WooCommerce plugin. The plugin fails to validate the identity of the requester when performing operations on abandoned-cart records. Specifically, the backend routines responsible for managing cart sessions do not verify that the request originated from a legitimate, authenticated source, nor do they validate the integrity of the request via a cryptographic nonce.\nThe exploitation flow begins when an attacker identifies the endpoint responsible for abandoned-cart record management. Because the plugin lacks necessary ownership checks, the application fails to verify whether the current user session is authorized to modify the target cart ID provided in the request parameters. An attacker can supply a specific customer cart record identifier, which the application then processes as a valid instruction to update or delete the data.\nThe lack of authentication requirements allows the application to execute destructive operations—such as deleting or altering cart contents—without any verification of the requester's identity or authorization status. The affected component handles these requests by directly applying the provided data to the underlying database records associated with the target identifier.\nIn a typical attack scenario, the threat actor observes the communication patterns of the plugin, identifies the vulnerable endpoint, and crafts an HTTP request (such as a POST or GET request) containing the targeted customer's cart identifier. Due to the absence of nonce-based CSRF protection or server-side authorization checks, the server processes the request and modifies the customer's cart record accordingly. This interaction requires no elevated privileges, and the network exposure is universal for any WordPress site running a vulnerable version of the plugin.\nThe post-exploitation impact includes the loss of customer shopping data and potential interference with sales funnels. By systematically targeting cart records, an attacker could negatively affect the store's conversion rates, delete legitimate customer orders in progress, or cause inconsistency in the abandoned-cart synchronization process between WooCommerce and Mailchimp."
}