CVE-2026-93549: CWE-352 Cross-Site Request Forgery (CSRF) in CoCart
Description
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
Affected software
CoCart
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93549 is a CSRF vulnerability in the CoCart WordPress plugin before version 4.9.7. The issue arises because the plugin does not scope its REST API authentication filter to only its own endpoints, effectively disabling the WordPress core REST nonce protection globally. An attacker can leverage this to perform CSRF attacks that create new administrator accounts using the session of a logged-in administrator.
Potential Impact
An attacker can create a new administrator account on a vulnerable WordPress site by exploiting this CSRF vulnerability, potentially gaining full administrative control. This compromises site integrity and security by allowing unauthorized privilege escalation.
Mitigation Recommendations
Upgrade CoCart to version 4.9.7 or later, where this vulnerability is fixed. No other mitigation is indicated or required as the fix is available in the official plugin update.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-18T09:25:32.032Z
- State
- PUBLISHED
Threat ID: 6ac1f64ea43b0b3b8943476e
Added to database: 10/04/2026, 06:46:38 UTC
Last enriched: 10/04/2026, 07:01:14 UTC
Last updated: 10/04/2026, 09:37:36 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.