SureCart vulnerability

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.

Published 6 Sep 2026Updated 6 Sep 20261 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.