Summary
CVE-2026-66465 is a critical unauthenticated authentication bypass vulnerability affecting the Cartify WooCommerce WordPress theme by AgniHD, versions up to and including 1.3.0.1. The flaw allows an attacker to bypass authentication controls through an alternate path or channel, resulting in account takeover without requiring credentials or user interaction. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: broken authentication logic classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), allowing an unauthenticated attacker to access or take over accounts through a path that does not enforce the theme’s normal authentication checks.
- Trigger conditions: no authentication or user interaction is required to exploit the flaw.
- Attack vector: network-based, exploitable remotely over HTTP(S) against any WordPress site running the vulnerable theme.
- Impact: full compromise of confidentiality, integrity, and availability, consistent with unauthorized account takeover (including potentially administrator accounts).
Affected software
- AgniHD Cartify WordPress theme, version 1.3.0.1 and all earlier versions.
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade the Cartify theme to the latest version available from the vendor/marketplace beyond 1.3.0.1, as soon as a fixed release is published.
- If no patch is confirmed available: Restrict or disable public access to the theme’s authentication-related functionality, monitor for anomalous account access or privilege changes, enforce multi-factor authentication on administrative accounts, and consider temporarily deactivating the theme or placing the site behind a web application firewall until a vendor fix is confirmed.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/themes/cartify/

