CVE-2026-18480
SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
| Vendor | unknown |
| Product | surecart |
| Published | Sep 6, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown surecart
Be the first to know when new high vulnerabilities affecting unknown surecart are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SureCart
4.0.0 < 4.6.3
References
Credits
Jakub Herman WPScan