Vulnerability in SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments — CVE-2026-75793
MediumSeverity
0.2%Estimated exploit probability
80,000+ sitesInstalls
4.7.0Fixed in
What to do now
Update SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments to 4.7.0 or later.
Affected versions
- Everything before 4.7.0
Affected: SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments (plugin, surecart)
What the vulnerability is
The SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments plugin for WordPress is vulnerable to unauthorized account creation in all versions up to 4.7.0 (exclusive). This makes it possible for unauthenticated attackers to register on sites where registration is disabled.