Impact
The ShopEngine Elementor WooCommerce Builder Addon contains a flaw in the rum_importer() function; the function is hooked to WordPress’s import_start event without checking the caller’s capability or filtering imported option names, allowing an attacker to inject arbitrary <wp_option> nodes into a WXR file and have them processed by update_option(). This lets an authenticated user set critical options such as users_can_register and default_role, effectively enabling the creation of new administrator accounts and full control of the site. The weakness is a classic privilege‑escalation vulnerability (CWE‑269).
Affected Systems
All instances of the ShopEngine Elementor WooCommerce Builder Addon up to and including version 4.9.4 on WordPress sites are affected. The product is distributed under the roxnor:ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets branding. No specific environment details are listed, but any WordPress site using the plugin will be vulnerable unless the vendor’s latest patch is applied.
Risk and Exploitability
The impact is high: an attacker who can reach the WordPress import flow—namely a user with Shop Manager or higher role—can gain full site control. The CVSS score of 7.2 reflects this severity, and while an EPSS score is not provided, the vulnerability allows a straightforward exploit path without additional prerequisites beyond authentication and import capability. Because the KEV catalog does not list this vulnerability, it is not currently part of any known exploitation campaign, but the technical ease of attack warrants immediate attention.
OpenCVE Enrichment