CVE-2026-92436 MEDIUM
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
WordPress
Mô tả
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 5.3 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| Ngày công bố | 13:17 27/09/2026 |
| Ngày cập nhật | 23:38 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 23:47 28/09/2026 | CREATED | cve | MEDIUM |