Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

wc_cart_hash Cookie – WooCommerce

wc_cart_hash is a session cookie set by the WooCommerce plugin for WordPress to detect changes in a visitor's shopping cart. It is strictly necessary for an online store to function and does not require visitor consent under ePrivacy rules.

Name
wc_cart_hash
Provider
WooCommerce
Category
Necessary
Type
HTTP cookie
Lifetime
Session
Consent
No, but it must be listed in the cookie policy

What is the wc_cart_hash cookie?

wc_cart_hash is a technical cookie set by WooCommerce, the most widely used e-commerce plugin for WordPress. It appears automatically on any site running WooCommerce as soon as a visitor adds a product to the cart or interacts with the store's shopping features.

The cookie is generated server-side by WooCommerce (PHP), not by a third-party script, and works alongside the related wc_cart_hash session mechanism used to track cart state.

Its purpose is purely functional: it lets WooCommerce detect whether a cached version of the cart differs from the actual cart contents, so the visitor always sees accurate cart information.

What data it stores

  • Content: a hash generated from the shopping cart's contents, not personal data itself
  • Value format: varies between installations depending on the WooCommerce setup and any caching plugins in use
  • Destination: the value is read and checked by the store's own server (WooCommerce), and is not sent to WooCommerce/Automattic or any other external provider
  • Duration: session cookie – deleted when the browser is closed

What it is used for

For the store owner, wc_cart_hash keeps the shopping cart working correctly when caching plugins are active on the site — a very common setup on WordPress/WooCommerce stores. Without it, a visitor could see an outdated, cached version of their cart instead of its actual contents.

In practice, the cookie lets the site compare the current cart hash with the stored one and refresh the displayed cart (e.g. item count or subtotal) whenever a difference is detected.

Does it require consent?

In CookieFix's classification, wc_cart_hash falls under strictly necessary. Under the ePrivacy Directive (implemented in Romania via Law 506/2004) and GDPR, cookies that are strictly necessary to provide a service explicitly requested by the user — here, an online store's shopping cart — are exempt from the prior consent requirement.

Site owners do not need to request consent for this cookie, but they must still disclose it in their cookie policy, including its purpose and duration, for transparency toward users.

How to block or delete wc_cart_hash

Visitors can delete or block this cookie from their browser settings (e.g. in Chrome: Settings → Privacy and security → Cookies). Blocking it may break the shopping cart's behavior, especially on sites with caching enabled.

Because it is strictly necessary, this cookie should not be auto-blocked by a consent management platform before consent is given, as that could prevent normal use of the store. A CMP like CookieFix can still correctly classify it during a scan and document it automatically in the cookie policy, without blocking it — unlike statistics or marketing cookies, which it can keep blocked until consent is obtained.

Frequently asked questions

It's a technical cookie set by WooCommerce that stores a hash of the shopping cart's contents, used to detect whether a cached version of the cart still matches its actual contents.

No. It's classified as strictly necessary for the online store to function, so it's exempt from the prior consent requirement under ePrivacy and GDPR.

It's a session cookie, meaning it's automatically deleted when the visitor closes their browser.

The shopping cart may show incorrect or outdated information, especially on sites using caching plugins, since the browser can no longer confirm whether the displayed version is current.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.