{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92436","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","state":"PUBLISHED","assignerShortName":"WPScan","dateReserved":"2026-09-16T10:16:35.087Z","datePublished":"2026-09-27T06:00:21.636Z","dateUpdated":"2026-09-27T06:00:21.636Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2026-09-27T06:00:21.636Z"},"title":"Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR","problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"affected":[{"vendor":"Unknown","product":"Mailchimp for WooCommerce","versions":[{"status":"affected","versionType":"semver","version":"0","lessThan":"6.3"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents."}],"references":[{"url":"https://wpscan.com/vulnerability/f4d7b94a-7699-464c-a646-5946837b363a/","tags":["exploit","vdb-entry","technical-description"]}],"credits":[{"lang":"en","value":"JunHee CHO","type":"finder"},{"lang":"en","value":"WPScan","type":"coordinator"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"WPScan CVE Generator"}}}}