Description
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
Published: 2026-09-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Account Creation
Action: Immediate Upgrade
AI Analysis

Impact

The vulnerability in the SureCart WordPress plugin allows an attacker to create a WordPress user account without any prior authentication. The plugin does not respect the site’s user registration setting and automatically logs the attacker in after account creation. The impact is the unauthorized creation and use of an account, potentially giving the attacker full access to the site’s administrative functions if the account receives elevated privileges.

Affected Systems

Users of the SureCart WordPress plugin running any version older than 4.7.0 are affected. The flaw manifests when the WordPress site has user registration disabled, yet the plugin still creates an account and establishes a session for that new user.

Risk and Exploitability

The CVSS score of 6.5 is declared, but the risk is high because creating a user account bypasses all registration controls. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating limited publish‑time exploitation data. The attack vector is likely based on unauthenticated web traffic; an attacker can trigger account creation by visiting a plugin route that creates a user. The lack of a restriction check makes the flaw straightforward to exploit in any exposed WordPress installation using this plugin before version 4.7.0.

Generated by OpenCVE AI on September 6, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SureCart to version 4.7.0 or later
  • If an upgrade is not possible, disable WordPress user registration globally to block account creation
  • Block the plugin’s account‑creation endpoint with a firewall rule or web‑application‑firewall to prevent unauthenticated requests

Generated by OpenCVE AI on September 6, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Surecart
Surecart surecart
Wordpress
Wordpress wordpress
Vendors & Products Surecart
Surecart surecart
Wordpress
Wordpress wordpress

Sun, 06 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 06 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
Title SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
References

Subscriptions

Surecart Surecart
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T10:44:55.786Z

Reserved: 2026-08-18T08:03:32.092Z

Link: CVE-2026-75793

cve-icon Vulnrichment

Updated: 2026-09-06T10:38:36.209Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T07:16:43.220

Modified: 2026-09-08T19:09:21.310

Link: CVE-2026-75793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T13:30:07Z

Weaknesses