PatchSiren

CoCart Headless CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CoCart Headless CVE published 2026-07-27

CVE-2026-59536

CVE-2026-59536 is a high-severity vulnerability in the CoCart – Headless ecommerce plugin, affecting versions up to 4.8.4. It allows unauthenticated broken access control, with a CVSS score of 7.5. This vulnerability has the potential for unauthorized access, making it critical for users of the plugin to apply patches. The vulnerability was publicly disclosed on 2026-07-27T15:17:04.203Z.