CVE-2026-73346 HIGH

CVE-2026-73346: WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability

Vendor Mailchimp
Product MailChimp For WooCommerce
Weakness CWE-89 · SQLi
Published August 13, 2026
Last update August 13, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.

Explanation of Vulnerability in Simple Terms

02Summary

MailChimp For WooCommerce versions before 6.2 contain a SQL injection vulnerability in database queries. An attacker with high-level site privileges can craft malicious input to read or modify database contents. The vulnerability affects the broader site scope and may expose sensitive customer or order data stored in the database.

What an attacker can do

03Attacker Capabilities

Read or modify database records by injecting SQL commands through the plugin.

Potential impact on your site

04Site Impact

Customer data, orders, and other database records could be exposed or altered by a compromised admin account.

Conditions required to exploit

05Prerequisites

Attacker must have high-level site privileges (administrator or equivalent role).

Key dates

06Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

08Related CVE