← WordPress Vulnerabilities
WordPress security by component

CoCart – Headless ecommerce

CoCart – Headless ecommerce is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: cart-rest-api-for-woocommerce

CVE-2026-59536: CoCart exposes an unauthenticated privileged operation

CoCart through 4.8.4 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the REST route, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version4.9.0
Safe version
Jul 27, 2026 CVE-2026-59536
CoCart exposes an unauthenticated privileged operation
CoCart through 4.8.4 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the REST route, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
4.9.0
CVE7.5
NVDPending
Jan 02, 2025 CVE-2023-47241
CoCart – Headless ecommerce: A security weakness
CoCart – Headless ecommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending