PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10524 CoCart CVE debrief

The CoCart WordPress plugin before 4.9.0 is affected by a vulnerability that allows unauthenticated users to manipulate product prices through public REST API endpoints. This issue has a CVSS score of 7.5 and is rated HIGH. Users should verify their affected scope and apply the vendor remediation. The CVE record was published on 2026-08-06T22:16:42.537Z and has not been modified since then. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance.

Vendor
CoCart
Product
CoCart WordPress plugin
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Users of the CoCart WordPress plugin, especially those using versions before 4.9.0, should verify their affected scope and apply the vendor remediation. Affected operators, platforms, vulnerability-management, and security teams should be aware of the potential impact. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retested remediated assets, and closed items should be tracked only after evidence is documented. Asset inventory checks for CoCart plugin versions before 4.9.0 are recommended. Additionally, verifying affected scope, applying vendor remediation, and implementing compensating controls are crucial for those who should care about this vulnerability. Those impacted should also conduct inventory checks and monitor for suspicious activity related to WooCommerce orders and product price manipulations through REST API endpoints. Security teams should prioritize patching or mitigating this vulnerability based on its HIGH CVSS score and potential operational impact on e-commerce sites using CoCart. They should also consider the credibility of sources like CVE.org and NVD when assessing the vulnerability's severity and scope. Furthermore, reviewing compensating controls and verifying the effectiveness of implemented mitigations are essential steps for ensuring the security of affected systems. Lastly, maintaining an up-to-date asset inventory and tracking changes to the CoCart plugin or WooCommerce environment can help in quickly identifying and addressing potential security issues related to this vulnerability. Therefore, users and administrators of the CoCart WordPress plugin should take immediate action to protect their systems from potential exploitation. This includes verifying the version of the CoCart plugin, applying the vendor remediation, and enhancing monitoring and detection capabilities for suspicious activities related to product price manipulations and unauthorized order completions. By taking these steps, they can significantly reduce the risk associated with this vulnerability and

Technical summary

The CoCart WordPress plugin before 4.9.0 does not validate user-supplied price values against actual product prices when adding items to the cart via public REST API endpoints. This allows unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals. The vulnerability has a CVSS score of 7.5 and is rated HIGH. Affected product context and defensive impact should be considered, and source-grounded technical framing should be applied without unsupported root-cause or exploit claims.

Defensive priority

CVE-2026-10524 is rated HIGH with a CVSS score of 7.5. Unaffected scope and compensating controls should be verified.

Recommended defensive actions

  • Verify affected scope and apply vendor remediation
  • Implement compensating controls and monitor for suspicious activity
  • Conduct inventory checks for CoCart plugin versions before 4.9.0
  • Review official advisories or CVE records to validate affected scope, severity, and vendor guidance
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints. Official records indicate this allows unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:42.537Z and has not been modified since then.