CVE-2026-66465: WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Affected Software
1 affected component
Cartify WordPress theme<=1.3.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Cartify themeto a version that resolves this vulnerability.Fixed in 1.3.0.1
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66465?
CVE-2026-66465 has a critical severity score of 9.8.
2
What does CVE-2026-66465 affect?
CVE-2026-66465 affects versions of the Cartify WordPress theme up to and including 1.3.0.1.
3
How do I fix CVE-2026-66465?
To remediate CVE-2026-66465, update the Cartify theme to the latest version.
4
What type of vulnerability is CVE-2026-66465?
CVE-2026-66465 is an Unauthenticated Broken Authentication vulnerability.
5
What are the potential impacts of CVE-2026-66465?
CVE-2026-66465 can lead to account takeover, allowing unauthorized access to user accounts.