ZeroHour

CVE-2026-18480

large

Broken Access Control Account Takeover in SureCart WordPress Plugin

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

The SureCart WordPress plugin before 4.6.3 contains an improper privilege management flaw (CWE-269): it does not verify that the account modified during a customer update is the same account its permission check authorized. A user with only a subscriber-level account can trigger the update and change the email address of another user, including an administrator, then take over that account through the standard password-reset flow. The flaw is compounded by the ability to associate an attacker-controlled customer record with an arbitrary user and by disclosure of customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber account alone. Any WordPress site running an affected version of the plugin is exposed, with administrator accounts the primary high-value targets. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.2% probability of exploitation within 30 days.

What to do: Upgrade the SureCart plugin to version 4.6.3 or later on every site where it is active. As an interim mitigation, restrict or disable open user registration and monitor for unexpected email-address changes on accounts, especially administrators. Admins who find unexplained email changes should reset credentials and review recent password-reset activity for signs of account takeover.

Affected
SureCart WordPress pluginall versions before 4.6.3 (< 4.6.3)
Estimated exposure
large≈ tens of thousands of sites (roughly 10,000–30,000 active installs; plugin directory figures, not provided in the source data) — The estimate is based on SureCart's active-install count on the WordPress.org plugin directory, which places the plugin in the low tens of thousands of installations — a niche e-commerce plugin far smaller than mainstream commerce plugins…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.