Description
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
Published: 2026-10-04
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross‑Site Request Forgery enabling unauthorized administrator account creation
Action: Apply Patch
AI Analysis

Impact

The CoCart plugin fails to restrict its REST API authentication filter only to its own endpoints, effectively disabling WordPress core’s nonce protection for every route. This flaw allows an attacker to perform a cross‑site request forgery attack that, without any additional credentials, creates a new administrator account using a logged‑in administrator’s session. The result is elevation of privileges to full site ownership, compromising confidentiality, integrity, and availability of the WordPress installation.

Affected Systems

WordPress sites running CoCart versions 4.9.0 through 4.9.6, the range of releases before 4.9.7. Any site that has not upgraded beyond 4.9.6 is vulnerable, regardless of other configuration settings.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, so the exploitation probability cannot be precisely quantified. The CVSS score is not supplied, but the functional impact—complete compromise of site administration—indicates a high‑severity risk. The attack vector is inferred from the description: an attacker can lure an authenticated administrator into visiting a malicious page that issues a crafted REST API request, exploiting the disabled nonce protection. No additional prerequisites beyond an active administrator session are stated, making exploitation feasible under typical conditions.

Generated by OpenCVE AI on October 4, 2026 at 08:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CoCart to version 4.9.7 or later to correct the authentication filter scoping issue.
  • Configure the web server or WAF to reject or tightly restrict REST API requests that lack a valid nonce, thereby mitigating the bypass of WordPress core's nonce protection.
  • Audit existing administrator accounts for unauthorized additions and remove any suspicious accounts.

Generated by OpenCVE AI on October 4, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-352

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
Title CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-04T06:00:23.901Z

Reserved: 2026-09-18T09:25:32.032Z

Link: CVE-2026-93549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:34.180

Modified: 2026-10-04T07:16:34.180

Link: CVE-2026-93549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T09:00:10Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-352

    Cross-Site Request Forgery (CSRF)