Impact
The Mailchimp for WooCommerce plugin prior to version 6.3 contains an unauthenticated information disclosure flaw. An attacker can supply a request‑sized identifier derived from a customer’s email address to load a saved shopping cart without authentication. This allows the attacker to verify that the person with that email has shopped at the site and to view the cart’s contents, exposing customer intent and potentially personal data. The vulnerability is an insecure direct object reference, allowing read‑only access to private data.
Affected Systems
The flaw affects the Mailchimp for WooCommerce WordPress plugin. Users running any version earlier than 6.3 are susceptible; the issue is present in all builds before 6.3. No specific sub‑versions are listed beyond the major version cutoff.
Risk and Exploitability
The vulnerability does not require prior authentication or knowledge of any system credentials; the exploit uses a public endpoint that accepts an email‑derived identifier. Because the attack is unauthenticated and the payload is trivial to construct, the risk of exploitation is high for any site that uses the plugin and has customers with known or guessable email addresses. No CVSS or EPSS score is available, but the nature of the flaw and the lack of mitigations in the affected versions indicate a serious information disclosure risk.
OpenCVE Enrichment