CVE-2026-17553
Deferred Deferred - Pending Action

Privilege Escalation in WP EasyCart Plugin

Vulnerability report for CVE-2026-17553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec_manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default_role='administrator' and users_can_register='1', then self-registering a new account that is assigned the administrator role.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_easycart wp_easycart to 5.9.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP EasyCart plugin for WordPress has a privilege escalation vulnerability in versions up to 5.9.3. An AJAX handler allows authenticated attackers with Store Manager access to update arbitrary WordPress options by passing any POST key directly into update_option() without restrictions. This can let attackers set default_role to administrator and enable user registration, then create an admin account.

Detection Guidance

Check if the WP EasyCart plugin version 5.9.3 or lower is installed on your WordPress site. Look for unauthorized privilege changes or new admin accounts in WordPress user management. Review server logs for suspicious AJAX requests to ec_ajax_save_page_default_options.

Impact Analysis

If you use the WP EasyCart plugin version 5.9.3 or earlier, an attacker with Store Manager access could escalate their privileges to administrator. This could allow them to take full control of your WordPress site, install malicious plugins, steal data, or deface your website.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. A successful exploit may expose sensitive user data, resulting in legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Update the WP EasyCart plugin to the latest version immediately. Remove any unauthorized admin accounts. Disable the plugin if not in use. Monitor for unusual privilege escalations or new user registrations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart