Junglewise Threat Intelligence

CVE-2026-59536: CoCart Headless ecommerce broken access control

CVE-2026-59536 · Severity: high · CVSS 7.5 · Published 2026-07-27

Executive brief

CoCart is a WordPress plugin that provides a specialized interface for building 'headless' online stores using WooCommerce. A security flaw in versions 4.8.4 and earlier allows unauthorized individuals to bypass access controls. This could potentially allow an attacker to modify store data or perform administrative actions without a valid login, impacting the integrity of the e-commerce site.

Technical details

A broken access control vulnerability exists in the CoCart – Headless ecommerce plugin for WordPress (versions <= 4.8.4) due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or access data that should be restricted to privileged users. The vulnerability is triggered via the plugin's REST API components. Successful exploitation allows an attacker to compromise the integrity of the store's data without requiring any user interaction or valid credentials. The issue is resolved in version 4.9.0.

Affected products

  • CoCart Headless CoCart – Headless ecommerce <= 4.8.4

Timeline

  • 2026-05-28: other: Reported by researcher VanTastic
  • 2026-07-23: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: NVD publication date
  • 2026-07-27: patched: Patch confirmed available in version 4.9.0

References

Related threats