PT-2026-81272 · WordPress · Shopengine Elementor Woocommerce Builder Addon

·

CVE-2026-75971

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution versions prior to 4.9.5
Description An issue exists where the rum importer() function is registered on the WordPress core import start action hook without a plugin-owned capability check or allowlist filtering. This allows authenticated attackers with Shop Manager-level access or higher to use a malicious WXR import file to pass arbitrary <wp option> name/value pairs directly to the update option() function. By manipulating options such as users can register and default role, an attacker can enable open self-registration of Administrator accounts, leading to a full site takeover. This occurs because the Shop Manager role possesses the import capability, granting access to the WordPress Importer flow.
Recommendations Update to a version newer than 4.9.4.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75971

Affected Products

Shopengine Elementor Woocommerce Builder Addon