WordPress Plugin Vulnerabilities

SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover

Description

The plugin does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.

Proof of Concept

Affects Plugins

Fixed in 4.6.3

References

Classification

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-04 (about 2 days ago)
Added
2026-09-04 (about 1 day ago)
Last Updated
2026-09-04 (about 1 day ago)

Other