PatchSiren

CoCart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CoCart CVE published 2026-08-06

CVE-2026-10524

The CoCart WordPress plugin before 4.9.0 is affected by a vulnerability that allows unauthenticated users to manipulate product prices through public REST API endpoints. This issue has a CVSS score of 7.5 and is rated HIGH. Users should verify their affected scope and apply the vendor remediation. The CVE record was published on 2026-08-06T22:16:42.537Z and has not been modified since then. Affected produ [truncated]