Price Manipulation Vulnerability in CoCart WordPress Plugin
CVE-2026-10524
Key Information:
Badges
What is CVE-2026-10524?
The CoCart WordPress plugin, especially in versions prior to 4.9.0, has a significant flaw where it does not properly validate user-supplied price values against the actual prices of products. This weakness allows unauthenticated users to bypass typical security measures, enabling them to set arbitrary prices when adding products to their cart via public REST API endpoints. Consequently, this can lead to a situation where users can complete WooCommerce orders at manipulated prices, raising serious concerns about potential financial loss and exploitation.
Affected Version(s)
CoCart 0 < 4.9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved