CVE · High

CVE-2026-73346 — Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-73346 Mailchimp for WooCommerce [mailchimp-for-woocommerce] < 6.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 6.2 6.2 2026-08-12

CVE-2026-73346

The Mailchimp for WooCommerce plugin for WordPress contains a vulnerability that allows attackers with administrator-level access to inject malicious SQL code into the system. This occurs because the plugin does not properly sanitize user input, allowing attackers to modify existing SQL queries and potentially extract sensitive database information. As a result, attackers can exploit this vulnerability to gain unauthorized access to the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.