Impact
The SureCart WordPress plugin for versions prior to 4.6.3 fails to verify that the account being updated matches the account authorized by the permission check. An authenticated user with subscriber‑level privileges can therefore change another user’s email address—including that of an administrator. The attacker can then trigger a password reset for the target account, gaining administrative control. This flaw exposes user credentials, allows privilege escalation, and permits full takeover of any account that the subscriber can target.
Affected Systems
This issue affects the SureCart WordPress plugin. Any installation of SureCart that is earlier than version 4.6.3 is vulnerable. The plugin’s permission checks are bypassed for subscriber accounts, allowing them to edit other users’ information until the update to 4.6.3 or later is applied.
Risk and Exploitability
The CVSS score is not publicly disclosed, and there is currently no EPSS score available. Based on the description, a subscriber‑level user who can authenticate to the site represents the likely attack vector. The flaw allows the attacker to modify another user’s email address and then reset their password, giving full administrative control of the target account. With a large number of subscriber accounts, the potential impact is high. The vulnerability is not listed in CISA’s KEV catalog, but the absence of a patch makes it a critical risk for affected sites.
OpenCVE Enrichment