SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75793

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SureCart plugin for WordPress versions prior to 4.7.0 is vulnerable as it allows unauthenticated users to create accounts and gain logged-in sessions without adhering to the site's user registration settings, even when registration is disabled. This can lead to unauthorized access and potential abuse of user privileges. WordPress administrators and site owners using this plugin should prioritize updating to version 4.7.0 or later to mitigate this risk.

CVE
CVE-2026-75793
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
WordPress

Original NVD Description

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.