Back Redpacketsecurity CVE Alert: CVE-2026-94107 – nivocart
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator’s email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.
**Risk verdict:** High risk and should be remediated promptly; no KEV, SSVC exploitation state, EPSS score or PoC indicator is supplied, so active exploitation cannot be confirmed.
Successful exploitation could provide unauthorised administrator access, enabling alteration of shop content, orders, pricing, customer data and configuration. An attacker could also create persistence, deface the storefront, redirect payments or use privileged access to support fraud and data theft.
Most likely attack path
The likely path is remote access to the administrative recovery function (AV:N), requiring no existing privileges or user interaction (PR:N, UI:N). Exploitation is not trivial (AC:H, with an additional attack requirement), but successful compromise has high confidentiality, integrity and availability consequences; Scope is unchanged, so direct impact is primarily within the affected application rather than automatic cross-system compromise.
Internet-facing shops with exposed administrator recovery endpoints, weak email-account protection, shared hosting, or unmaintained extensions are the highest-risk deployments. Multi-store operators and sites handling payment or personal data warrant extra scrutiny.
Review recovery requests, token failures and administrator logins for unusual volume or geography.
Correlate recovery activity with successful privileged logins shortly afterwards.
Alert on new administrators, changed payment settings, exports and unexpected template modifications.
Inspect web logs for repeated requests to the recovery endpoint without normal user journeys.
Mitigation and prioritisation
Apply the vendor’s security fix or upgrade beyond the affected release; treat as urgent.
If no fix is available, disable administrator password recovery and restrict the admin path by VPN or allow-list.
Force administrator password resets, revoke active sessions and enable MFA where supported.
Add rate limiting, short-lived single-use tokens and monitoring; test changes carefully in staging.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
