plugin

Cart Rest Api For Woocommerce Vulnerabilities

3 known security issues reported for the Cart Rest Api For Woocommerce WordPress plugin. Most recent disclosed Jul 23, 2026.

3 medium

Running Cart Rest Api For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

CoCart – Headless REST API for WooCommerce <= 4.8.4 - Missing Authorization

medium

The CoCart – Headless REST API for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.8.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.8.4
Fixed in:
4.9.0
Disclosed:
Jul 23, 2026

CVE-2026-59536 on NVD →

CoCart <= 4.8.0 - Unauthenticated Price Manipulation

medium

The CoCart plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 4.8.0. This is due to a lack of server-side payment verification. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 4.8.0
Fixed in:
4.9.0
Disclosed:
Jul 20, 2026

CVE-2026-10524 on NVD →

CoCart – Headless ecommerce <= 3.11.2 - Missing Authorization

medium

The CoCart – Headless ecommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of data due to a missing capability check on an unknown function in versions up to, and including, 3.11.2. This makes it possible for unauthenticated attackers to make unauthorized use of the...

CVSS:
5.3
Affected:
up to 3.11.2
Fixed in:
3.12.0
Disclosed:
Nov 7, 2023

CVE-2023-47241 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database