The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 27 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress-extensions
Wordpress-extensions mailchimp For Woocommerce |
|
| Vendors & Products |
Wordpress-extensions
Wordpress-extensions mailchimp For Woocommerce |
Sun, 27 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 |
Sun, 27 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents. | |
| Title | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-27T06:00:21.636Z
Reserved: 2026-09-16T10:16:35.087Z
Link: CVE-2026-92436
No data.
Status : Received
Published: 2026-09-27T06:17:22.490
Modified: 2026-09-27T06:17:22.490
Link: CVE-2026-92436
No data.
OpenCVE Enrichment
Updated: 2026-09-27T11:42:21Z
Weaknesses