Impact
Unauthenticated broken access control is present in WordPress CoCart – Headless ecommerce Plugin versions 4.8.4 and earlier. The flaw permits attackers to invoke protected API endpoints without authentication, potentially creating orders, manipulating cart contents, or executing other privileged actions. The weakness corresponds to CWE‑862, indicating absent or insufficient authorization checks. As a result, confidentiality, integrity, and availability of the e‑commerce data and operations can be compromised by anyone with network access to the site.
Affected Systems
The vulnerability affects installations of the CoCart – Headless ecommerce plugin from the vendor CoCart Headless. All versions up to and including 4.8.4 are impacted; versions 4.9.0 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity condition. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is through exposed REST API endpoints that lack sufficient access controls, meaning a remote attacker could exploit the flaw without authentication. Once engaged, the attacker can perform any actions that a privileged user would normally be permitted, leading to significant business impact.
OpenCVE Enrichment