Executive brief
CoCart is a popular WordPress REST API plugin that adds shopping cart functionality to WooCommerce stores. The plugin fails to validate product prices supplied by users through its public API endpoints, allowing attackers to set arbitrary prices on items and complete orders at fraudulent totals without authentication. This directly impacts online store revenue and enables order fraud at scale.
Technical details
The vulnerability is a price validation bypass in CoCart's add-item REST API endpoint (/wp-json/cocart/v2/cart/add-item). When an unauthenticated user adds an item to the cart, the plugin accepts a user-supplied "price" parameter without verifying it against the actual product price in WooCommerce. An attacker can obtain a valid session/cart key via guest checkout, then manipulate item prices to arbitrary values (e.g., setting a $100 product to $1) via the CoCart-API-Cart-Key header. The modified price persists in the shared WooCommerce cart and is reflected in the final order total, enabling order completion at fraudulent prices. The attack requires WooCommerce and CoCart to be active with guest checkout enabled, but no authentication is required. Patches are available in version 4.9.0 and later.
Affected products
- CoCart CoCart before 4.9.0
Timeline
- 2026-07-20: disclosed
- 2026-08-06: advisory: NVD publication
- 2026-08-06: patched: Fixed in version 4.9.0