« Volver al listado

Mailchimp

Mailchimp FOR Woocommerce: vulnerabilidades y CVE

Mailchimp FOR Woocommerce tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92437Media (5.3)0.22%—3 oct 2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data,…
CVE-2026-92436Media (5.3)0.24%—27 sept 2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email…
CVE-2026-92435Media (5.3)0.30%—19 sept 2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated…
CVE-2026-73346Alta (7.6)0.38%—13 ago 2026
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2022-2556Baja (2.7)0.77%—29 ago 2022
The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is…
CVE-2022-2267Media (4.3)0.71%—29 ago 2022
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1
  4. T1210 Exploitation of Remote Services1
  5. T1565.001 Stored Data Manipulation1
  6. T1592.004 Client Configurations1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mailchimp