Important Security Patch for CoCart Community v4.9.7 This release hardens how CoCart's REST authentication check is scoped, ensuring WordPress's own request verification is not bypassed on other REST endpoints. Recommend that you update to this release as soon as possible.

Sep 30, 2026 · 3:16 PM UTC

1
2
39
The patch has also been backported for v4.9.0 - v4.9.6 should you rollback or need to reinstall that version. None of them should be left exposed, so the fix has been applied directly to each of those releases, both on GitHub and on WordPress dot org.
21
Sort replies: Relevant Recent Liked