PT-2026-99501 · WordPress · Mailchimp For Woocommerce

·

CVE-2026-92436

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mailchimp for WooCommerce WordPress plugin versions prior to 6.3
Description An issue exists where the plugin fails to require authentication or verify ownership when loading a saved cart. An unauthenticated attacker who possesses a customer's email address can use a request-supplied identifier derived from that email to confirm the customer's shopping history at the store and access the contents of their saved cart.
Recommendations Update Mailchimp for WooCommerce WordPress plugin to version 6.3 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92436

Affected Products

Mailchimp For Woocommerce