Impact
The ShopEngine Elementor WooCommerce Builder Addon for WordPress allows an attacker to exploit a cross‑site request forgery vulnerability on one of its authentication endpoints. This flaw lets an unauthenticated user force a victim browser to log into an attacker‑controlled account. As the victim subsequently enters billing and shipping information during checkout, those personal data fields are stored under the attacker's account and become readable by the attacker, constituting a privacy violation.
Affected Systems
Users running ShopEngine version prior to 4.9.3 on WordPress sites are affected. The vulnerable plugin, sold as an Elementor WooCommerce builder addon, is commonly installed on WordPress e‑commerce sites; any installation of these versions without an updated patch is at risk.
Risk and Exploitability
The absence of a CSRF token allows exploitation with only a crafted HTTP request, so the attack can be carried out remotely with no local privileges. The vulnerability can be exploited by any entity able to host a malicious site or send a forged request to the target. The exploit is straightforward: the attacker induces a victim to visit a crafted link that posts to the vulnerable authentication endpoint, thereby logging the victim into an account of the attacker’s choice. Once logged in, the victim’s shipping and billing details are saved to the attacker’s account, enabling the attacker to read the PII. No additional credentials are required, and the risk is high for confidentiality. The exploit probability is not quantified by EPSS and the issue is not listed in the CISA KEV catalog, but the simplicity of the attack vector warrants caution and swift remediation.
OpenCVE Enrichment