Περιγραφή
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user-s identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user-s email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user-s password and gain access to their account if the customer ID is known.
CVSS 8.1EPSS 0.32%Κίνδυνος 0.83
Προβολή πηγής- Δημοσίευση
- 2026-07-11 06:16:10
- Επηρεαζόμενες εκδόσεις
- <=4.2.3
- Τύπος
- Εφαρμογή ιστού
- Διάνυσμα
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H