CVE-2026-93549

NONE
Updated Oct 04, 2026
Unknown
Parameter Value
Affected Versions before 4.9.7
Type CWE-352 Cross-Site Request Forgery (CSRF)
Vendor Unknown
Public PoC No

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.

Vulnerable Products

unknown:cocart