PT-2026-104610 · WordPress · Cocart
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CoCart WordPress plugin versions prior to 4.9.7
Description
The plugin fails to scope its REST API authentication filter to its own endpoints. This action disables the REST nonce protection provided by WordPress core for every route. Consequently, an attacker can execute a cross-site request forgery attack to create a new administrator account by leveraging the session of a currently logged-in administrator.
Recommendations
Update CoCart WordPress plugin to version 4.9.7 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cocart