Tag
#SureCart
Critical Vulnerability in SureCart WordPress Plugin Allows Account Takeover
The SureCart WordPress plugin before version 4.6.3 is vulnerable to an account takeover exploit, allowing users with subscriber-level accounts to change the email address of any user, including administrators, and take over their account via a password reset. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected versions are 4.0.0 to 4.6.2, and the recommended fix is to upgrade to version 4.6.3 or later. Organizations using SureCart should prioritize patching to prevent potential account takeovers.
Understanding and Defending Against CVE-2026-7655: Privilege Escalation in SureCart Plugin
CVE-2026-7655 is a privilege escalation vulnerability in the SureCart plugin for WordPress, allowing unauthenticated attackers to takeover accounts by manipulating user details via webhook events. This vulnerability has a CVSS score of 8.1 and affects versions up to 4.2.3 of the plugin. Understanding the root cause and attack vector is crucial for defenders to implement effective mitigations.