CyberRota Analysis
AI-GeneratedThe CoCart WordPress plugin prior to version 4.9.7 lacks proper scoping of its REST API authentication filter, compromising the nonce protection provided by WordPress core. This vulnerability enables attackers to execute cross-site request forgery (CSRF) attacks, potentially leading to the creation of new administrator accounts through an authenticated administrator's session. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of unauthorized access.
Original NVD Description
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.