Export limit exceeded: 399421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92435 | 1 Wordpress-extensions | 1 Mailchimp For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. | ||||
| CVE-2026-92436 | 1 Wordpress-extensions | 1 Mailchimp For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents. | ||||
Page 1 of 1.