CVE-2026-10524: CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
Published Aug 6, 2026
·Updated
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
Affected Software
1 affected component
WordPress plugin CoCart<4.9.0
Event History
Aug 6, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-10524?
The severity of CVE-2026-10524 is rated as high with a score of 7.5.
2
How do I fix CVE-2026-10524?
To fix CVE-2026-10524, update the CoCart plugin to version 4.9.0 or later.
3
What type of vulnerability is CVE-2026-10524?
CVE-2026-10524 is an unauthenticated arbitrary price manipulation vulnerability.
4
Who is affected by CVE-2026-10524?
Users of the CoCart WordPress plugin before version 4.9.0 are affected by CVE-2026-10524.
5
What is the impact of CVE-2026-10524?
The impact of CVE-2026-10524 is that unauthenticated users can manipulate product prices and complete WooCommerce orders.