Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.
https://jvn.jp/en/jp/JVN22220399/
https://forums.cubecart.com/topic/58736-cubecart-653-released-security-update/