Description
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
Published: 2026-09-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the SureCart WordPress plugin allows an attacker to create a WordPress user account without any prior authentication. The plugin does not respect the site's user registration setting and automatically logs the attacker in after account creation. The impact is the unauthorized creation and use of an account, potentially giving the attacker full access to the website’s administrative functions if the account receives elevated privileges.

Affected Systems

Users of the SureCart WordPress plugin running any version older than 4.7.0 are affected. The flaw manifests when the WordPress site has user registration disabled, yet the plugin still creates an account and establishes a session for that new user.

Risk and Exploitability

The CVSS score is not declared, but the risk is high because creating a user account bypasses all registration controls. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating limited publish‑time exploitation data. The attack vector is likely based on unauthenticated web traffic; an attacker can trigger account creation by visiting a plugin route that creates a user. The lack of a restriction check makes the flaw straightforward to exploit in any exposed WordPress installation using this plugin before version 4.7.0.

Generated by OpenCVE AI on September 6, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SureCart to version 4.7.0 or later
  • If an upgrade is not possible, disable WordPress user registration globally to block account creation
  • Verify that the plugin configuration no longer creates user accounts regardless of the registration setting

Generated by OpenCVE AI on September 6, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 06 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
Title SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T06:00:04.015Z

Reserved: 2026-08-18T08:03:32.092Z

Link: CVE-2026-75793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-06T07:16:43.220

Modified: 2026-09-06T07:16:43.220

Link: CVE-2026-75793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T07:30:03Z

Weaknesses