Mailchimp
Mailchimp FOR Woocommerce: vulnerabilidades y CVE
Mailchimp FOR Woocommerce tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92437 | Media (5.3) | 0.22% | — | 3 oct 2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data,… |
| CVE-2026-92436 | Media (5.3) | 0.24% | — | 27 sept 2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email… |
| CVE-2026-92435 | Media (5.3) | 0.30% | — | 19 sept 2026 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated… |
| CVE-2026-73346 | Alta (7.6) | 0.38% | — | 13 ago 2026 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |
| CVE-2022-2556 | Baja (2.7) | 0.77% | — | 29 ago 2022 | The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is… |
| CVE-2022-2267 | Media (4.3) | 0.71% | — | 29 ago 2022 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.