PT-2026-88789 · Levelfourstorefront · Shopping Cart & Ecommerce Store
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec ajax save page default options() AJAX handler iterating over every $ POST key and passing it directly into update option() without any allowlist, while gating the handler only on 'manage options' OR the plugin's custom 'wpec manager' capability. The plugin's built-in 'wpec store manager' role holds 'wpec manager' but not 'manage options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default role='administrator' and users can register='1', then self-registering a new account that is assigned the administrator role.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopping Cart & Ecommerce Store