CVE-2026-93549: CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CoCart WordPress pluginto a version that resolves this vulnerability.Fixed in 4.9.7
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites running CoCart versions 4.9.0 through 4.9.6 are exposed when an administrator is logged in and can be induced to make a cross-site request. The affected authentication filter disables WordPress REST nonce protection for every REST route, not only CoCart endpoints.
What does an attacker need to exploit it?
An attacker needs to cause a logged-in WordPress administrator to perform a cross-site request. The attack relies on that administrator's active session and can create a new administrator account.
Are sites running a fixed version affected?
No. The issue affects CoCart versions before 4.9.7; upgrading to version 4.9.7 or later removes the affected version range.
How can I check for possible compromise?
Review WordPress administrator accounts for newly created or unrecognized accounts, especially accounts created while an administrator may have been logged in on a site running an affected CoCart version. Also confirm the installed CoCart version and whether it is 4.9.0 through 4.9.6.