PT-2026-99501 · WordPress · Mailchimp For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mailchimp for WooCommerce WordPress plugin versions prior to 6.3
Description
An issue exists where the plugin fails to require authentication or verify ownership when loading a saved cart. An unauthenticated attacker who possesses a customer's email address can use a request-supplied identifier derived from that email to confirm the customer's shopping history at the store and access the contents of their saved cart.
Recommendations
Update Mailchimp for WooCommerce WordPress plugin to version 6.3 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mailchimp For Woocommerce