A checkout appears to show another customer’s cart
Treat the report as a possible failure to keep customer content separate. Preserve the affected page type, observation time, guest or signed-in context and category of unexpected content in a restricted incident record. Escalate promptly to the person authorized to contain exposure and the technical owners of sessions and caching. Do not begin with routine cache clearing that could obscure the evidence. WooCommerce requires Cart, Checkout and My Account to remain dynamic, but that requirement does not prove caching caused this report.
For: An owner or operator of a research-only store who has received a report that checkout displays content belonging to someone else.
Preserve the observation without spreading the content
Record what the observer actually saw: unexpected cart lines, another person's contact details, an order reference or account content. These categories have different implications. Unexpected products alone do not establish whose cart they are; visible personal details warrant urgent assessment even when the cause is unknown. Keep the first observation separate from any later technical conclusion.
Use the page's path without private query tokens, the date and time with time zone, the browser context and whether the person was a guest or signed in. Record whether the device or browser was shared if that is known. Do not ask the observer to open another person's order, change its contents or submit payment to demonstrate the issue.
If an existing screenshot is necessary for the responsible investigator, keep it in the business's restricted incident location and use a redacted working copy for broader discussion. The worksheet below needs a content category and evidence reference, not the disclosed name, address or cart contents. Avoid copying cookies, session tokens or complete network captures into ordinary support messages.
Separate account context from the caching hypothesis
WooCommerce documents guest checkout and account creation as separate settings. Record the actual state involved instead of assuming that every checkout visitor has an account. A report from a shared browser, a guest visit and a signed-in account can each require a different investigation. None of those labels establishes permission to see someone else's information.
WooCommerce's caching guidance says Cart, Checkout and My Account must remain dynamic. Some caching tools already exclude those pages. The responsible maintainer should inspect the assigned routes and the real host, cache-plugin and session configuration, including whether documented exclusions actually cover the affected route. The database exclusion for _wc_session_ depends on the host or plugin; it is not a universal switch.
The same guidance describes cookies that distinguish carts. It does not identify the cause of an observed disclosure on your installation. A cache rule that looks wrong is an investigative lead; the technical assessment must connect it to the response the visitor received. Do not disable all caching or security controls on that basis.
Give containment authority and evidence to the right owners
Notify the person who may restrict access to the affected function and the contracted technical contact responsible for the site. Ask for a named incident owner, the immediate containment decision and the evidence that must be retained. Evidence preservation should not delay necessary containment of an ongoing exposure; record the time, reason and authorizer of any urgent change.
The WooCommerce system status report can identify site addresses, installed versions, plugins, theme overrides and the assigned cart and checkout pages. Use that inventory to identify the installation and owners involved. Keep the full report inside the agreed technical channel and share only what the recipient needs. A list of plugins does not establish which one caused the problem.
Ask the host or cache owner to preserve relevant configuration and existing diagnostic records before routine clearing, and the application owner to assess session and access behavior. If cache clearing is part of authorized containment, record what was changed and when. A disappearance after clearing is evidence of a changed symptom, not a complete explanation of who could previously see what.
Close the technical question before treating checkout as restored
The incident record should distinguish reported exposure, confirmed observations, affected scope still unknown, containment completed and assessment still pending. Ask the technical owner what evidence supports the cause and the boundary of affected content. A single normal page load does not establish that customer isolation has been restored across the relevant guest and account paths.
Any legal notification question depends on the actual facts and applicable obligations and should go to the business's responsible adviser. This worksheet does not classify a legal breach or determine notification deadlines.
For a Prism checkout-review consultation, provide the website, research-only product context, platform and a redacted description of the checkout question. Confirm scope, responsibilities, fees and terms before work. A public inquiry is not incident staffing or authorization to change the site; customer records, screenshots containing private details and credentials stay out of that form.
Personalized-content incident
Use this as an index to restricted evidence, not a copy of exposed customer data. Separate reported facts from confirmed findings. An unknown cause or affected scope remains open after a cache change.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Personalized-content incident. The last column is for temporary notes.
Incident fact
Evidence to preserve
Decision it informs
Your record
Affected page type
Evidence to preservePath without private tokens; Cart, Checkout, My Account or another actual route; assigned page from site settings.
Decision it informsWhich function may need containment and which configuration the maintainer must inspect.
Observed content category
Evidence to preserveDescribe unexpected items, contact fields, order details or account content without copying their values; reference restricted evidence.
Decision it informsWhether the report concerns a cart mismatch alone or apparent disclosure of personal content.
Time and visitor context
Evidence to preserveObservation timestamp and zone, guest or signed-in state, known shared-device context and what action preceded it.
Decision it informsWhich existing technical records can be correlated without asking the observer to explore further.
Cache or session owner
Evidence to preserveName the responsible host, cache component and application maintainer from actual configuration and agreements.
Decision it informsWho can preserve the relevant rules and assess session separation; a component name is not a cause.
Containment authority
Evidence to preserveAuthorized decision maker, affected function, approved action and time performed.
Decision it informsWho may limit exposure and what was changed before the investigation concluded.
Assessment and reopening basis
Evidence to preserveTechnical finding reference, scope still unknown and evidence supporting restored isolation.
Decision it informsWhether containment can end or an unresolved finding still requires action.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
WooCommerce documentation establishes configuration requirements, not the cause, scope or legal classification of an incident on your store.
Do not inspect other customers' records to reproduce the problem or put customer content, card details, cookies, tokens or credentials into this worksheet or the public consultation form.
Prism consultation scope must be agreed; this page makes no incident-response hours or restoration promise.
WooCommerce system status report — checked 2026-09-21. The report identifies site addresses, WordPress and WooCommerce versions, plugins, theme and template overrides, and cart and checkout page assignments. It can locate the installation, not prove the cause of a disclosure.
WooCommerce accounts and privacy — checked 2026-09-29. Guest checkout and account creation have separate settings; the incident record should identify the actual visitor state.
WooCommerce caching configuration — checked 2026-09-29. Cart, Checkout and My Account must remain dynamic and may already be excluded by caching tools. Session database exclusions depend on the host or plugin; cart cookies distinguish carts. These facts do not establish a particular disclosure's cause.
Prism solutions — checked 2026-09-21. Public support includes storefront review, processing preparation and help with a provider's website questions. Scope, fees and terms are agreed before work; the provider decides eligibility and account terms.
Prism contact — checked 2026-09-21. The form asks for the website, products and question, excluding card details, passwords and customer records. Follow-up is by email; the request does not book an appointment, purchase a service or submit a processing application.