Vulnerabilities and security researches formailchimp-for-woocommerce mailchimp-for-woocommerce
Direction: descendingOct 05, 2026
Mailchimp for WooCommerce # CVE-2026-92437
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 03, 2026
- Research Description
- The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
- Affected versions
-
max 6.3.
- Status
-
vulnerable
Sep 29, 2026
Mailchimp for WooCommerce # CVE-2026-92436
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 27, 2026
- Research Description
- The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
- Affected versions
-
max 6.3.
- Status
-
vulnerable
Sep 22, 2026
Mailchimp for WooCommerce # CVE-2026-92435
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 19, 2026
- Research Description
- The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
- Affected versions
-
max 6.1.1.
- Status
-
vulnerable
Aug 14, 2026
Mailchimp for WooCommerce # CVE-2026-73346
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 13, 2026
- Research Description
- Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
- Affected versions
-
max 6.2.
- Status
-
vulnerable
Jun 25, 2026
Mailchimp for WooCommerce # PSC-2026-64671
- PSC, Research URL
- Home page URL
- Application
- Date
- Jun 25, 2026
- Research Description
- Email marketing integrations process order activity, customer profiles, product metadata, cart events, and API credentials. That makes them useful for store communication, but also security-sensitive because customer related data moves between WooCommerce and an external marketing platform. Mailchimp for WooCommerce version 6.1.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64671, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for WooCommerce customer sync, order data handling, API credentials, and marketing automation workflows.
- Affected versions
-
Min 6.3, max 6.3.
- Status
-
SAFE & CERTIFIED
Jun 07, 2024
Mailchimp for WooCommerce # CVE-2022-2267
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 29, 2022
- Research Description
- The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
- Affected versions
-
max 2.7.1.
- Status
-
vulnerable
Mailchimp for WooCommerce # CVE-2022-2556
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 29, 2022
- Research Description
- The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
- Affected versions
-
max 2.7.2.
- Status
-
vulnerable
Mailchimp for WooCommerce # 3f5dfa2ebe9baa0e66335bd7bc38b9469abe4dfc
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 22, 2017
- Research Description
- Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 2.1.2 WordPress MailChimp for WooCommerce plugin <= 2.1.1 - Local File Inclusion WordPress MailChimp for WooCommerce plugin is prone to a Local File Inclusion vulnerability in 2.1.2 version. The vulnerability was in /admin/partials/tabs/notices.php file in if ( isset ( $_GET['error_notice'] ) ... IF conditional statement which lead to include(__DIR__.'/errors/'.$_GET['error_notice'].'.php'); local file inclusion.
- Affected versions
-
max 2.1.2.
- Status
-
vulnerable