---
id: CVE-2026-92437
title: >-
  The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require
  authentication, a nonce or an ownership check before it acts on a customer's
  abandoned-cart record identified from request-supplied data, allowing an
  unauthentica…
summary: >-
  The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require
  authentication, a nonce or an ownership check before it acts on a customer's
  abandoned-cart record identified from request-supplied data, allowing an
  unauthentica…
severity: none
cwe:
  - CWE-862
product: Mailchimp for WooCommerce
affected:
  - mailchimp_for_woocommerce < 6.3
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:46.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92437'
references:
  - url: 'https://wpscan.com/vulnerability/47b3aa17-f7fd-42df-9ef0-e33b5da8f955/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.567Z'
---

## Overview

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
