Executive brief
The Mailchimp for WooCommerce WordPress plugin fails to authenticate requests before loading customer saved carts, allowing an attacker with knowledge of a customer's email address to view that customer's shopping cart contents. An attacker can exploit this to confirm whether specific email addresses are customers of a store and to harvest details about their shopping behavior and saved items.
Technical details
The plugin derives a cart identifier from a customer's email address and loads the saved cart without verifying authentication or ownership, creating an IDOR (Insecure Direct Object Reference) vulnerability. An unauthenticated network attacker who knows a customer's email can request that identifier and read the cart contents. This affects versions before 6.3, which added proper access controls.
Affected products
- Mailchimp Mailchimp for WooCommerce before 6.3
Timeline
- 2026-09-25: disclosed
- 2026-09-27: patched: Version 6.3 includes fix