CVE-2026-10524 | CoCart Plugin up to 4.8.x on WordPress REST API Endpoint price external control of assumed-immutable web parameter
A vulnerability was found in CoCart Plugin up to 4.8.x on WordPress. It has been classified as problematic. This affects an unknown function of the component REST API Endpoint. This manipulation of the argument price causes external control of assumed-immutable web parameter.
This vulnerability appears as CVE-2026-10524. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More