[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#CVE-2026-18480

articleHIGH 8.8

Critical Vulnerability in SureCart WordPress Plugin Allows Account Takeover

The SureCart WordPress plugin before version 4.6.3 is vulnerable to an account takeover exploit, allowing users with subscriber-level accounts to change the email address of any user, including administrators, and take over their account via a password reset. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected versions are 4.0.0 to 4.6.2, and the recommended fix is to upgrade to version 4.6.3 or later. Organizations using SureCart should prioritize patching to prevent potential account takeovers.

Sep 6, 20261 source