PT-2026-104610 · WordPress · Cocart

·

CVE-2026-93549

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CoCart WordPress plugin versions prior to 4.9.7
Description The plugin fails to scope its REST API authentication filter to its own endpoints. This action disables the REST nonce protection provided by WordPress core for every route. Consequently, an attacker can execute a cross-site request forgery attack to create a new administrator account by leveraging the session of a currently logged-in administrator.
Recommendations Update CoCart WordPress plugin to version 4.9.7 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93549

Affected Products

Cocart