Description
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass authorization checks and access restricted data or functionality within the SureCart WordPress plugin. Because the check is missing, an attacker could potentially retrieve or modify sensitive transaction information, view user details, or alter payment orders, thereby impacting confidentiality, integrity, or availability of e‑commerce operations.

Affected Systems

All installations of the SureCart WordPress plugin up to and including version 4.6.2 are affected. The flaw exists within the plugin’s back‑end components that manage cart and checkout processes on WordPress sites.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the issue over the web without authentication, likely by sending crafted HTTP requests to administrative endpoints that the plugin exposes. The lack of any existing active exploit evidence suggests a low to moderate likelihood of exploitation at present, but the unauthenticated nature and potential impact warrant timely remediation.

Generated by OpenCVE AI on August 6, 2026 at 15:24 UTC.

Remediation

Vendor Solution

Update the WordPress SureCart plugin to the latest available version (at least 4.6.3).


OpenCVE Recommended Actions

  • Update the SureCart plugin to at least version 4.6.3 to apply the vendor‑supplied fix.
  • If an upgrade cannot be performed immediately, restrict access to the plugin’s administrative URLs with firewall or .htaccess rules so that only authenticated users or trusted IP addresses can reach them.
  • Audit the WordPress site for other unpatched plugins and apply the latest security updates for all components to reduce the risk of similar access‑control weaknesses.

Generated by OpenCVE AI on August 6, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Surecart
Surecart surecart
Wordpress
Wordpress wordpress
Vendors & Products Surecart
Surecart surecart
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Title WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Surecart Surecart
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:18.592Z

Reserved: 2026-03-12T11:12:38.876Z

Link: CVE-2026-32548

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:45:02Z

Weaknesses