PT-2026-71394 · WordPress · Shopengine Elementor Woocommerce Builder Addon
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ShopEngine Elementor WooCommerce Builder Addon versions prior to 4.9.3
Description
An authentication endpoint is not protected against Cross-Site Request Forgery (CSRF), a type of attack that forces an authenticated user to execute unwanted actions on a web application. This flaw allows an attacker to log a victim into an account controlled by the attacker. Consequently, any billing and shipping details the victim enters during the checkout process are stored under and can be read by the attacker.
Recommendations
Update ShopEngine Elementor WooCommerce Builder Addon to version 4.9.3 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopengine Elementor Woocommerce Builder Addon