PT-2026-71394 · WordPress · Shopengine Elementor Woocommerce Builder Addon

·

CVE-2026-19088

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ShopEngine Elementor WooCommerce Builder Addon versions prior to 4.9.3
Description An authentication endpoint is not protected against Cross-Site Request Forgery (CSRF), a type of attack that forces an authenticated user to execute unwanted actions on a web application. This flaw allows an attacker to log a victim into an account controlled by the attacker. Consequently, any billing and shipping details the victim enters during the checkout process are stored under and can be read by the attacker.
Recommendations Update ShopEngine Elementor WooCommerce Builder Addon to version 4.9.3 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19088

Affected Products

Shopengine Elementor Woocommerce Builder Addon