The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
CVE-2026-93549
NONE
Updated Oct 04, 2026
Unknown
unknown:cocart
CVE Details
CVE ID
CVE-2026-93549
Published Date
Oct 04, 2026
Vendor
Unknown
Severity
NONE
Impact
Minimal impact
Source
View Advisory