Junglewise Threat Intelligence

CVE-2021-47932: TheCartPress WordPress plugin privilege escalation in AJAX handler

CVE-2021-47932 · Severity: critical · CVSS 9.8 · Published 2026-05-10

Executive brief

TheCartPress, an eCommerce shopping cart plugin for WordPress, contains a critical security flaw that allows unauthorized individuals to create new administrator accounts. By sending a specially crafted request to the website, an attacker can gain full control over the site without needing any existing login credentials. This could lead to complete site takeover, theft of customer data, or the installation of malicious software.

Technical details

A missing authorization vulnerability (CWE-862) exists in TheCartPress plugin for WordPress up to version 1.5.3.6. The flaw is located within the AJAX handler for the 'tcp_register_and_login_ajax' action. An unauthenticated remote attacker can send a POST request to '/wp-admin/admin-ajax.php' with the 'tcp_role' parameter set to 'administrator'. This allows the attacker to register a new account with full administrative privileges. The plugin has been closed and removed from the WordPress plugin directory due to this security issue, and users are advised to migrate to an alternative eCommerce solution.

Affected products

  • TheCartPress TheCartPress eCommerce Shopping Cart <= 1.5.3.6

Timeline

  • 2021-10-04: disclosed: Exploit code published by researcher spacehen
  • 2021-10-05: other: Plugin closed on WordPress.org due to security issue
  • 2026-05-10: advisory: NVD/VulnCheck advisory published

References