CVE-2026-92436
Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
| Vendor | unknown |
| Product | mailchimp for woocommerce |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mailchimp for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown mailchimp for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Mailchimp for WooCommerce
0 < 6.3
References
Credits
JunHee CHO WPScan