CVE-2026-19088
Received Received - Intake

CSRF in ShopEngine WooCommerce Builder Addon

Vulnerability report for CVE-2026-19088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: WPScan

Description

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpengine shopengine to 4.9.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in the ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before version 4.9.3. An attacker can trick a victim into logging into an attacker-controlled account. Any billing or shipping details entered by the victim during checkout are then stored under the attacker's account and become accessible to them.

Detection Guidance

To detect this vulnerability, check the installed version of the ShopEngine Elementor WooCommerce Builder Addon plugin. If the version is below 4.9.3, the system is vulnerable. You can verify the version via WordPress admin panel under Plugins or by inspecting the plugin files on the server.

Impact Analysis

If you use the vulnerable plugin version, an attacker could force you to log into their account without your knowledge. Your entered billing or shipping details during checkout would then be accessible to the attacker, potentially leading to misuse of your personal or financial information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and potentially HIPAA's safeguards for protected health information. Organizations may face compliance breaches, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update the ShopEngine Elementor WooCommerce Builder Addon plugin to version 4.9.3 or later. This version contains the fix for the CSRF vulnerability. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart