The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
cve CVE-2026-93549 2 sources, 2 claims · Watch
NVD writes:
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session. the claim
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | unknown/cocartNVD says “Unknown · CoCart” |
| made_by | unknownNVD says “Unknown” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss | NVD | 8.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "CoCart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.9.7",
"status": "affected",
"version": "4.9.0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session."
}
],
"id": "CVE-2026-93549",
"lastModified": "2026-10-05T11:17:01.620",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-93549",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:50:22.503687Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-04T07:16:34.180",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-352"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | CoCartreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "CoCart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.9.7",
"status": "affected",
"version": "4.9.0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session."
}
],
"id": "CVE-2026-93549",
"lastModified": "2026-10-05T11:17:01.620",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-93549",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:50:22.503687Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-04T07:16:34.180",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-352"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | GitHub advisories | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-93549",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.",
"ghsa_id": "GHSA-9p8w-fmwq-692f",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-9p8w-fmwq-692f",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-9p8w-fmwq-692f"
},
{
"type": "CVE",
"value": "CVE-2026-93549"
}
],
"nvd_published_at": "2026-10-04T07:16:34Z",
"published_at": "2026-10-04T09:30:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-93549",
"https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff",
"https://github.com/advisories/GHSA-9p8w-fmwq-692f"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to...",
"type": "unreviewed",
"updated_at": "2026-10-04T09:30:28Z",
"url": "https://api.github.com/advisories/GHSA-9p8w-fmwq-692f",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "CoCart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.9.7",
"status": "affected",
"version": "4.9.0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session."
}
],
"id": "CVE-2026-93549",
"lastModified": "2026-10-05T11:17:01.620",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-93549",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:50:22.503687Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-04T07:16:34.180",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-352"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Unknownreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "CoCart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.9.7",
"status": "affected",
"version": "4.9.0",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session."
}
],
"id": "CVE-2026-93549",
"lastModified": "2026-10-05T11:17:01.620",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-93549",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:50:22.503687Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-04T07:16:34.180",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-352"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session. zetlyn/cve-nvd · 2026-10-04 | cvss 8.8 product CoCart status Received vendor Unknown | source |
| The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to... zetlyn/cve-ghsa · 2026-10-04 | severity unknown | source |