CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
Summary
| CVE | CVE-2026-93549 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-04 07:16:34 UTC |
| Updated | 2026-10-04 07:16:34 UTC |
| Description | The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session. |
Risk And Classification
Problem Types: CWE-352 Cross-Site Request Forgery (CSRF)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Naoki Kawahigashi (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.