Security
Loading…

CVE-2026-75793

MEDIUMCVSS 6.5
Description

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.

Timeline
Published:September 6th, 2026 7:16 AM
Last modified:September 6th, 2026 11:18 AM
CVSS Scoring

CVSS v3: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute