Improper Authentication Vulnerability in Mailchimp for WooCommerce Plugin
CVE-2026-92437
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-92437?
The Mailchimp for WooCommerce plugin prior to version 6.3 contains a vulnerability that permits unauthenticated attackers to manipulate or remove another user's abandoned cart records. This exploit occurs due to the lack of necessary authentication, nonce verification, or ownership checks when handling requests based on supplied data. As a result, malicious entities could gain unauthorized access to sensitive customer information, potentially leading to significant data integrity issues.
Affected Version(s)
Mailchimp for WooCommerce 0 < 6.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.