๐Ÿ” CVE Alert

CVE-2026-19088

UNKNOWN 0.0

ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.

Vendor unknown
Product shopengine elementor woocommerce builder addon
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown shopengine elementor woocommerce builder addon

Be the first to know when new unknown vulnerabilities affecting unknown shopengine elementor woocommerce builder addon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ShopEngine Elementor WooCommerce Builder Addon
0 < 4.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f58066e9-8066-43bc-8778-7ded279e8ee2/

Credits

Farid Narimanov WPScan