SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-76009

HIGH · CVSS 8.1 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to an authentication bypass due to improper permission settings on its REST API endpoint, allowing unauthenticated attackers to exploit it by using a hardcoded token. This vulnerability can lead to arbitrary SQL execution, including the creation of administrator accounts, and arbitrary file deletion, potentially resulting in full site takeover. WordPress site administrators using this plugin should prioritize immediate patching or mitigation to safeguard against unauthorized access and potential data breaches.

CVE
CVE-2026-76009
Severity
HIGH
CVSS
8.1
EPSS
0.52%
WordPress

Original NVD Description

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option('nextcart_token', '__token__')` when the `nextcart_token` option has not yet been written to the database. This makes it possible for unauthenticated attackers to bypass authentication to the migration endpoint by supplying the literal string `__token__` as the token, gaining access to privileged handlers that pass attacker-controlled SQL directly to `$wpdb->query()` and `$wpdb->get_results()` — enabling arbitrary SQL execution including administrator account creation — and pass an attacker-controlled path to `unlink()`, enabling arbitrary file deletion and full site takeover. The hardcoded fallback is reachable whenever the `nextcart_token` option has not yet been populated, which occurs after WP-CLI, network, or programmatic plugin activation without a subsequent authenticated `wp-admin` visit, as token generation is deferred to `admin_init` via `register_settings()`.