OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93549

HIGH · CVSS 8.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The CoCart WordPress plugin prior to version 4.9.7 lacks proper scoping of its REST API authentication filter, compromising the nonce protection provided by WordPress core. This vulnerability enables attackers to execute cross-site request forgery (CSRF) attacks, potentially leading to the creation of new administrator accounts through an authenticated administrator's session. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of unauthorized access.

CVE
CVE-2026-93549
Severity
HIGH
CVSS
8.8
EPSS
0.14%
WordPress

Original NVD Description

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.