๐Ÿ” CVE Alert

CVE-2026-18480

HIGH 8.8

SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.

Vendor unknown
Product surecart
Published Sep 6, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown surecart

Be the first to know when new high vulnerabilities affecting unknown surecart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / SureCart
4.0.0 < 4.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/88839ada-9c59-44cb-96e6-3548e5a59b9f/

Credits

Jakub Herman WPScan