CVE-2026-92436: Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Stores using Mailchimp for WooCommerce versions before 6.3 are affected. Any customer with a saved cart may have their store association and saved cart contents exposed.
What does an attacker need to exploit it?
No authentication is required. The attacker needs to know a customer's email address, which is used to derive the request-supplied identifier for the saved cart.
What information can be disclosed?
An attacker can confirm that a person associated with a known email address shops at the store and can read that customer's saved cart contents.