Impact
The SureCart WordPress plugin before version 4.6.3 fails to confirm that the account being updated is the one authorized by the permission check. Consequently, an authenticated subscriber can alter another user's email address—including that of an administrator—then trigger a password reset for the target account. The flaw also allows an attacker‑controlled customer record to be associated with any user and exposes customer identifiers and email addresses to any authenticated user, making the takeover reachable from subscriber‑level accounts alone.
Affected Systems
This vulnerability affects installations of the SureCart WordPress plugin released before version 4.6.3. All users running the plugin on WordPress sites are susceptible, regardless of whether they have subscriber or administrator accounts, because the flaw can be exploited by any authenticated subscriber.
Risk and Exploitability
The CVSS score of 8.8 points to a high severity, and no EPSS score is currently available. The flaw is not listed in the CISA KEV catalog, but the lack of a public patch increases the risk for affected sites. Exploitation requires a legitimate subscriber‑level login, which is commonly granted to paying customers. Once logged in, an attacker can change another member's email address, reset the target's password, and gain full control of that account. Because a site may host many subscriber accounts, the potential impact on administrative functions and data integrity is substantial.
OpenCVE Enrichment