CVE-2026-18480
Received Received - Intake

Email Address Change in SureCart WordPress Plugin

Vulnerability report for CVE-2026-18480, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-06

Last updated on: 2026-09-06

Assigner: WPScan

Description

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-06
Last Modified
2026-09-06
Generated
2026-09-06
AI Q&A
2026-09-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
surecart surecart to 4.6.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The SureCart WordPress plugin before version 4.6.3 has a vulnerability where insufficient authorization checks during customer updates allow users with subscriber-level access to change another user's email address, including administrators. This enables account takeover via password reset. Attackers can also link their customer records to arbitrary user accounts and view customer identifiers and email addresses, making the attack possible from a basic subscriber role.

Detection Guidance

Check the installed version of the SureCart plugin using WordPress admin panel or via command line. Run: wp plugin list --name=surecart. If the version is below 4.6.3, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability allows attackers with subscriber access to take over administrator accounts, potentially gaining full control of the WordPress site. It also exposes sensitive customer data like email addresses and identifiers to any authenticated user, increasing privacy risks and enabling further attacks.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data (email addresses) and potential data breaches. It may also breach HIPAA if customer data includes protected health information, as unauthorized access could compromise confidentiality requirements.

Mitigation Strategies

Update the SureCart plugin to version 4.6.3 or later immediately. Disable subscriber-level access temporarily if possible until the update is applied. Review user accounts for unauthorized email changes or suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18480. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart