Description
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated broken access control is present in WordPress CoCart – Headless ecommerce Plugin versions 4.8.4 and earlier. The flaw permits attackers to invoke protected API endpoints without authentication, potentially creating orders, manipulating cart contents, or executing other privileged actions. The weakness corresponds to CWE‑862, indicating absent or insufficient authorization checks. As a result, confidentiality, integrity, and availability of the e‑commerce data and operations can be compromised by anyone with network access to the site.

Affected Systems

The vulnerability affects installations of the CoCart – Headless ecommerce plugin from the vendor CoCart Headless. All versions up to and including 4.8.4 are impacted; versions 4.9.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity condition. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is through exposed REST API endpoints that lack sufficient access controls, meaning a remote attacker could exploit the flaw without authentication. Once engaged, the attacker can perform any actions that a privileged user would normally be permitted, leading to significant business impact.

Generated by OpenCVE AI on August 3, 2026 at 17:37 UTC.

Remediation

Vendor Solution

Update the WordPress CoCart – Headless ecommerce Plugin to the latest available version (at least 4.9.0).


OpenCVE Recommended Actions

  • Update the WordPress CoCart – Headless ecommerce Plugin to version 4.9.0 or later
  • Restrict the plugin’s REST API endpoints to authenticated roles only, using plugin settings or firewall rules
  • Apply role‑based access controls or whitelist specific user roles that can access e‑commerce functionality

Generated by OpenCVE AI on August 3, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Cocart Headless
Cocart Headless cocart – Headless Ecommerce
Wordpress
Wordpress wordpress
Vendors & Products Cocart Headless
Cocart Headless cocart – Headless Ecommerce
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Title WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Cocart Headless Cocart – Headless Ecommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T15:06:23.333Z

Reserved: 2026-07-05T21:27:50.222Z

Link: CVE-2026-59536

cve-icon Vulnrichment

Updated: 2026-07-27T15:06:19.878Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:04.203

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses