Description
The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec_manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default_role='administrator' and users_can_register='1', then self-registering a new account that is assigned the administrator role.
Published: 2026-09-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Administrator via arbitrary WordPress options
Action: Apply Patch
AI Analysis

Impact

An authenticated attacker with Store Manager privileges can trigger the ec_ajax_save_page_default_options AJAX action, which loops over every key sent in the POST payload and writes each to the WordPress options table without restriction. By setting options such as default_role to administrator and enabling user registration, the attacker can later create a new account that receives administrator rights, effectively elevating their privileges. This flaw arises from missing input validation and improper authorization checks (CWE‑269).

Affected Systems

WordPress sites that have the Levelfourstorefront Shopping Cart & eCommerce Store plugin version 5.9.3 or earlier installed. These versions are vulnerable when the plugin is present on the site; users with the wpec_manager role, or any higher capability, are impacted.

Risk and Exploitability

The CVSS score of 7.2 reflects a moderate to high severity. EPSS is not available, so the probability of exploitation cannot be quantified. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no known widespread exploitation at this time. The likely attack vector is an authenticated web request to the plugin’s AJAX endpoint, and the attacker does not need any special network access beyond normal site privileges.

Generated by OpenCVE AI on September 9, 2026 at 11:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP EasyCart to version 5.9.4 or later, which removes the unrestricted option update logic.
  • If an upgrade is not immediately possible, reconfigure the plugin or WordPress to restrict the wpec_manager role from executing the ec_ajax_save_page_default_options AJAX action, effectively blocking unauthorized option writes.
  • Monitor the WordPress options table for unexpected changes to entries such as default_role or users_can_register, and review new user registrations for elevated roles.

Generated by OpenCVE AI on September 9, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Levelfourstorefront
Levelfourstorefront shopping Cart \& Ecommerce Store
Wordpress
Wordpress wordpress
Vendors & Products Levelfourstorefront
Levelfourstorefront shopping Cart \& Ecommerce Store
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpec_manager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as default_role='administrator' and users_can_register='1', then self-registering a new account that is assigned the administrator role.
Title Shopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Levelfourstorefront Shopping Cart \& Ecommerce Store
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:13:26.504Z

Reserved: 2026-07-27T12:44:14.951Z

Link: CVE-2026-17553

cve-icon Vulnrichment

Updated: 2026-09-09T13:13:19.011Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:17:56.607

Modified: 2026-09-09T15:33:34.467

Link: CVE-2026-17553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:45:10Z

Weaknesses
  • CWE-269

    Improper Privilege Management