[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#SureCart

articleHIGH 8.8

Critical Vulnerability in SureCart WordPress Plugin Allows Account Takeover

The SureCart WordPress plugin before version 4.6.3 is vulnerable to an account takeover exploit, allowing users with subscriber-level accounts to change the email address of any user, including administrators, and take over their account via a password reset. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected versions are 4.0.0 to 4.6.2, and the recommended fix is to upgrade to version 4.6.3 or later. Organizations using SureCart should prioritize patching to prevent potential account takeovers.

Sep 6, 20261 source
blogHIGH 8.1

Understanding and Defending Against CVE-2026-7655: Privilege Escalation in SureCart Plugin

CVE-2026-7655 is a privilege escalation vulnerability in the SureCart plugin for WordPress, allowing unauthenticated attackers to takeover accounts by manipulating user details via webhook events. This vulnerability has a CVSS score of 8.1 and affects versions up to 4.2.3 of the plugin. Understanding the root cause and attack vector is crucial for defenders to implement effective mitigations.

Jul 12, 20261 source