CVE-2026-19088
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
| Vendor | unknown |
| Product | shopengine elementor woocommerce builder addon |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown shopengine elementor woocommerce builder addon
Be the first to know when new unknown vulnerabilities affecting unknown shopengine elementor woocommerce builder addon are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / ShopEngine Elementor WooCommerce Builder Addon
0 < 4.9.3
References
Credits
Farid Narimanov WPScan