CVE-2026-75793
SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
| Vendor | unknown |
| Product | surecart |
| Published | Sep 6, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown surecart
Be the first to know when new medium vulnerabilities affecting unknown surecart are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SureCart
0 < 4.7.0
References
Credits
Jakub Herman WPScan