What the vulnerability does
01Description
Missing Authorization vulnerability in CoCart Headless CoCart – Headless ecommerce cart-rest-api-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoCart – Headless ecommerce: from n/a through <= 3.11.2.
Explanation of Vulnerability in Simple Terms
02Summary
CoCart Headless ecommerce versions up to 3.11.2 lack proper authorization checks on certain API endpoints. An unauthenticated attacker can read sensitive information by making direct requests to the affected endpoints. The vulnerability does not allow modification or deletion of data, only unauthorized disclosure of information.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without authentication.
Potential impact on your site
04Site Impact
Customer or business data may be exposed to unauthorized parties without your knowledge.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 2, 2025
CVE published
April 29, 2026
Record updated