Impact
The CoCart plugin fails to restrict its REST API authentication filter only to its own endpoints, effectively disabling WordPress core’s nonce protection for every route. This flaw allows an attacker to perform a cross‑site request forgery attack that, without any additional credentials, creates a new administrator account using a logged‑in administrator’s session. The result is elevation of privileges to full site ownership, compromising confidentiality, integrity, and availability of the WordPress installation.
Affected Systems
WordPress sites running CoCart versions 4.9.0 through 4.9.6, the range of releases before 4.9.7. Any site that has not upgraded beyond 4.9.6 is vulnerable, regardless of other configuration settings.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, so the exploitation probability cannot be precisely quantified. The CVSS score is not supplied, but the functional impact—complete compromise of site administration—indicates a high‑severity risk. The attack vector is inferred from the description: an attacker can lure an authenticated administrator into visiting a malicious page that issues a crafted REST API request, exploiting the disabled nonce protection. No additional prerequisites beyond an active administrator session are stated, making exploitation feasible under typical conditions.
OpenCVE Enrichment