CVE-2026-66465
Received Received - Intake

Unauthenticated Broken Authentication in Cartify

Vulnerability report for CVE-2026-66465, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Patchstack

Description

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cartify cartify to 1.3.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-66465 is an unauthenticated broken authentication vulnerability in the WordPress Cartify Theme versions up to 1.3.0.1. It allows attackers to perform actions restricted to higher-privileged users without authentication, potentially gaining admin access to the website.

Detection Guidance

Since there is no official patch yet, detection may involve checking for unauthorized admin access or suspicious activity in WordPress logs. Monitor for unusual user creation or privilege escalation events. Patchstack's mitigation rule can help block exploitation attempts.

Impact Analysis

This vulnerability can lead to complete website compromise, including admin access, data theft, or malicious modifications. Attackers may exploit it remotely without user interaction, posing a critical risk to all websites using affected versions.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA due to unauthorized access risks, potential data breaches, and lack of proper authentication controls. Organizations may face legal penalties or reputational damage if exploited.

Mitigation Strategies

Apply Patchstack's mitigation rule immediately to block attacks. Avoid using the Cartify theme until an official patch is released. Consider switching to an alternative theme or updating to a patched version if available. Contact your hosting provider for assistance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66465. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart