๐Ÿ” CVE Alert

CVE-2026-93549

UNKNOWN 0.0

CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.

Vendor unknown
Product cocart
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cocart

Be the first to know when new unknown vulnerabilities affecting unknown cocart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / CoCart
4.9.0 < 4.9.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/

Credits

Naoki Kawahigashi WPScan