🚨 CVE-2026-75793
The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
🎖@cveNotify
WPScan
SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
See details on SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login CVE 2026-75793. View the latest Plugin Vulnerabilities on WPScan.

September 6, 2026 22