CVE-2026-100143: FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker only needs to know the email address of an existing guest customer. No authentication is required, and the checkout flow does not verify that the attacker controls that email address.
Which customer accounts are exposed?
Existing guest customer records are exposed. The issue allows an attacker to obtain a logged-in account associated with the supplied guest customer's email address and stored customer record.
What version resolves the issue?
Upgrade FluentCart to version 1.6.5 or later. Versions before 1.6.5 are affected.