CVE-2026-18480
largeBroken Access Control Account Takeover in SureCart WordPress Plugin
The SureCart WordPress plugin before 4.6.3 contains an improper privilege management flaw (CWE-269): it does not verify that the account modified during a customer update is the same account its permission check authorized. A user with only a subscriber-level account can trigger the update and change the email address of another user, including an administrator, then take over that account through the standard password-reset flow. The flaw is compounded by the ability to associate an attacker-controlled customer record with an arbitrary user and by disclosure of customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber account alone. Any WordPress site running an affected version of the plugin is exposed, with administrator accounts the primary high-value targets. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.2% probability of exploitation within 30 days.
What to do: Upgrade the SureCart plugin to version 4.6.3 or later on every site where it is active. As an interim mitigation, restrict or disable open user registration and monitor for unexpected email-address changes on accounts, especially administrators. Admins who find unexplained email changes should reset credentials and review recent password-reset activity for signs of account takeover.
| SureCart WordPress plugin | all versions before 4.6.3 (< 4.6.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.