Junglewise Threat Intelligence

CVE-2026-92436: Mailchimp for WooCommerce IDOR in saved cart loading

CVE-2026-92436 · Severity: info · Published 2026-09-27

Executive brief

The Mailchimp for WooCommerce WordPress plugin fails to authenticate requests before loading customer saved carts, allowing an attacker with knowledge of a customer's email address to view that customer's shopping cart contents. An attacker can exploit this to confirm whether specific email addresses are customers of a store and to harvest details about their shopping behavior and saved items.

Technical details

The plugin derives a cart identifier from a customer's email address and loads the saved cart without verifying authentication or ownership, creating an IDOR (Insecure Direct Object Reference) vulnerability. An unauthenticated network attacker who knows a customer's email can request that identifier and read the cart contents. This affects versions before 6.3, which added proper access controls.

Affected products

  • Mailchimp Mailchimp for WooCommerce before 6.3

Timeline

  • 2026-09-25: disclosed
  • 2026-09-27: patched: Version 6.3 includes fix

References

Related threats