CVE-2026-75793: Unknown Surecart

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.

Affected products

  • Unknown Surecart: before 4.7.0 (fixed in 4.7.0)

Published 2026-09-06. Last modified 2026-09-08.