CVE-2026-92436 PUBLISHED

Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR

Assigner: WPScan
Reserved: 16.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.

Product Status

Vendor Unknown
Product Mailchimp for WooCommerce
Versions Default: unaffected
  • affected from 0 to 6.3 (excl.)

Credits

  • JunHee CHO finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE