Description
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Published: 2026-08-13
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Cartify theme versions up to 1.3.0.1 allows unauthenticated actors to hijack user accounts due to a broken authentication mechanism. This flaw is identified as an improper authentication error (CWE-288). Attackers who exploit this can gain access to any user account on the site, potentially creating, deleting, or modifying site content and configuration.

Affected Systems

WordPress sites that have the AgniHD Cartify theme at or below version 1.3.0.1 are affected. Any site deploying this theme or earlier releases is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly reported exploitation at this time. Based on the description, the flaw permits unauthenticated bypass of the theme’s authentication, enabling account takeover. The exact method of triggering the bypass is not detailed in the CVE description.

Generated by OpenCVE AI on August 13, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cartify theme to version 1.3.0.2 or later, which fixes the authentication flaw
  • Reset passwords for all site accounts after the upgrade to ensure compromised credentials are invalidated
  • Enable detailed logging and monitor logs for anomalous authentication attempts or unauthorized content changes

Generated by OpenCVE AI on August 13, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Title WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:30:16.995Z

Reserved: 2026-07-27T09:00:40.310Z

Link: CVE-2026-66465

cve-icon Vulnrichment

Updated: 2026-08-13T15:30:10.860Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:07.833

Modified: 2026-08-13T16:18:44.987

Link: CVE-2026-66465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel