PT-2026-81272 · WordPress · Shopengine Elementor Woocommerce Builder Addon
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution versions prior to 4.9.5
Description
An issue exists where the
rum importer() function is registered on the WordPress core import start action hook without a plugin-owned capability check or allowlist filtering. This allows authenticated attackers with Shop Manager-level access or higher to use a malicious WXR import file to pass arbitrary <wp option> name/value pairs directly to the update option() function. By manipulating options such as users can register and default role, an attacker can enable open self-registration of Administrator accounts, leading to a full site takeover. This occurs because the Shop Manager role possesses the import capability, granting access to the WordPress Importer flow.Recommendations
Update to a version newer than 4.9.4.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopengine Elementor Woocommerce Builder Addon