PT-2026-88789 · Levelfourstorefront · Shopping Cart & Ecommerce Store

·

CVE-2026-17553

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec ajax save page default options() AJAX handler iterating over every $ POST key and passing it directly into update option() without any allowlist, while gating the handler only on 'manage options' OR the plugin's custom 'wpec manager' capability. The plugin's built-in 'wpec store manager' role holds 'wpec manager' but not 'manage options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default role='administrator' and users can register='1', then self-registering a new account that is assigned the administrator role.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17553

Affected Products

Shopping Cart & Ecommerce Store