{"id":"CVE-2026-92436","title":"The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an una…","summary":"The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an una…","severity":"none","cwe":["CWE-639"],"product":"Mailchimp for WooCommerce","affected":["mailchimp_for_woocommerce < 6.3"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:22.490","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92436","references":[{"url":"https://wpscan.com/vulnerability/f4d7b94a-7699-464c-a646-5946837b363a/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.832Z","slug":"CVE-2026-92436","body":"## Overview\n\nThe Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}