Authentication Bypass Vulnerability in Next-Cart Store Plugin for WooCommerce by WordPress
CVE-2026-76009
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-76009?
The Next-Cart Store to WooCommerce Migration plugin for WordPress has a significant authentication bypass vulnerability. Attackers can exploit this flaw by interacting with the /wp-json/next_cart/v1/migration REST route, which erroneously allows access due to a permissive callback setting. The plugin relies on a default hardcoded value for the nextcart_token, which can be exploited by unauthorized users to gain access to sensitive migration functionalities. This vulnerability facilitates the execution of arbitrary SQL commands and could lead to unauthorized account creation and file deletions, posing a severe risk to the website's security, especially when initialized through WP-CLI, network, or during programmatic plugin activation without proper admin verification.
Affected Version(s)
Next-Cart Store to WooCommerce Migration 0 <= 3.9.8