WordPress Plugin Vulnerabilities

FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email

Description

The plugin does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.

Proof of Concept

Affects Plugins

Fixed in 1.6.5

References

Classification

Miscellaneous

Original Researcher
Mutantgun
Submitter
Mutantgun
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 21 hours ago)
Added
2026-09-28 (about 7 hours ago)
Last Updated
2026-09-28 (about 7 hours ago)

Other