What is CVE-2026-10524?
CVE-2026-10524 is a vulnerability in the CoCart WordPress plugin before version 4.9.0 that lacks validation of user-supplied prices against actual product prices. Through public REST API endpoints, unauthenticated users can set arbitrary prices for items added to the cart, potentially completing WooCommerce orders at manipulated costs. Updating the plugin to version 4.9.0 or higher is the recommended mitigation.
Azərbaycanca: CVE-2026-10524: CoCart WordPress plugin-in 4.9.0-dan əvvəlki versiyalarında bir zəiflik aşkarlanıb. Bu, autentifikasiya olunmamış istifadəçilərə REST API endpoint-ləri vasitəsilə səbətə məhsul əlavə edərkən real məhsul qiymətindən asılı olmayaraq özbaşına qiymət təyin etməyə və WooCommerce sifarişlərini aşağı qiymətlə tamamlamağa imkan verən qiymət doğrulama çatışmazlığıdır. Plugin-i 4.9.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of the CoCart plugin are affected by CVE-2026-10524?
CVE-2026-10524 affects the CoCart WordPress plugin versions prior to 4.9.0.
What can an attacker do by exploiting CVE-2026-10524?
An unauthenticated attacker can set an arbitrary price for items added to the cart via REST API endpoints, regardless of the actual product price. This allows WooCommerce orders to be completed at manipulated, lower costs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.