Description
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
Published: 2026-09-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SureCart WordPress plugin for versions prior to 4.6.3 fails to verify that the account being updated matches the account authorized by the permission check. An authenticated user with subscriber‑level privileges can therefore change another user’s email address—including that of an administrator. The attacker can then trigger a password reset for the target account, gaining administrative control. This flaw exposes user credentials, allows privilege escalation, and permits full takeover of any account that the subscriber can target.

Affected Systems

This issue affects the SureCart WordPress plugin. Any installation of SureCart that is earlier than version 4.6.3 is vulnerable. The plugin’s permission checks are bypassed for subscriber accounts, allowing them to edit other users’ information until the update to 4.6.3 or later is applied.

Risk and Exploitability

The CVSS score is not publicly disclosed, and there is currently no EPSS score available. Based on the description, a subscriber‑level user who can authenticate to the site represents the likely attack vector. The flaw allows the attacker to modify another user’s email address and then reset their password, giving full administrative control of the target account. With a large number of subscriber accounts, the potential impact is high. The vulnerability is not listed in CISA’s KEV catalog, but the absence of a patch makes it a critical risk for affected sites.

Generated by OpenCVE AI on September 6, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SureCart plugin to version 4.6.3 or later.
  • Reset all administrator passwords immediately after applying the update.
  • Review user permissions and restrict subscriber‑level users from editing other users’ email addresses until the fix is deployed.

Generated by OpenCVE AI on September 6, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Surecart
Surecart surecart
Wordpress
Wordpress wordpress
Weaknesses CWE-269
CWE-285
CWE-639
Vendors & Products Surecart
Surecart surecart
Wordpress
Wordpress wordpress

Sun, 06 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
Title SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover
References

Subscriptions

Surecart Surecart
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T06:00:03.840Z

Reserved: 2026-07-31T12:29:08.541Z

Link: CVE-2026-18480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-06T07:16:43.097

Modified: 2026-09-06T07:16:43.097

Link: CVE-2026-18480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T07:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key