Authentication Bypass Vulnerability in Next-Cart Store Plugin for WooCommerce by WordPress
CVE-2026-76009

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

What is CVE-2026-76009?

The Next-Cart Store to WooCommerce Migration plugin for WordPress has a significant authentication bypass vulnerability. Attackers can exploit this flaw by interacting with the /wp-json/next_cart/v1/migration REST route, which erroneously allows access due to a permissive callback setting. The plugin relies on a default hardcoded value for the nextcart_token, which can be exploited by unauthorized users to gain access to sensitive migration functionalities. This vulnerability facilitates the execution of arbitrary SQL commands and could lead to unauthorized account creation and file deletions, posing a severe risk to the website's security, especially when initialized through WP-CLI, network, or during programmatic plugin activation without proper admin verification.

Affected Version(s)

Next-Cart Store to WooCommerce Migration 0 <= 3.9.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Samuele Santonicola
.