The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
CVE-2026-75793
NONE
Updated Sep 06, 2026
WordPress
CVE Details
CVE ID
CVE-2026-75793
Published Date
Sep 06, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory