Sceawere

Vulnerability Detail

CVE-2026-19088UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ShopEngine CSRF Account Login Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
15h ago
Vendor
Unknown
Product
ShopEngine Elementor WooCommerce Builder Addon
Attack Type
CWE-352 Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-13T06:17:38.230Z",
  "pubdate": "2026-08-13T06:17:38.230Z",
  "executiveSummary": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the ShopEngine Elementor WooCommerce Builder Addon WordPress plugin prior to version 4.9.3.\nThe flaw stems from a lack of adequate cryptographic request validation or anti-CSRF token protection on an authentication endpoint.\nAn unauthenticated, remote attacker can exploit this security weakness by tricking an authenticated victim into executing a malicious request, effectively forcing the victim's browser to log into an attacker-controlled account.\nThe primary impact of this vulnerability is session manipulation and data exposure during the e-commerce checkout workflow.\nIf successfully exploited, any sensitive billing and shipping details entered by the victim during the subsequent checkout process are stored under the attacker's account profile.\nConsequently, the attacker gains unauthorized access to the victim's personally identifiable information (PII) and financial-related address data.\nThe risk implications include privacy violations, potential data exfiltration, and compromised user confidentiality within the affected WordPress environment.\nExploitation requires the attacker to successfully induce a victim to interact with a crafted malicious link or visit a third-party website while maintaining an active session or interacting with the vulnerable WordPress site.",
  "technicalDetails": "The root cause of the vulnerability is the absence of anti-CSRF mechanisms (such as nonces) on a specific authentication endpoint handled by the ShopEngine Elementor WooCommerce Builder Addon WordPress plugin.\nBecause the application fails to validate the origin of the state-changing authentication request, it blindly processes the incoming HTTP request.\nThe vulnerable component is the authentication functionality exposed by the ShopEngine Elementor WooCommerce Builder Addon plugin for versions prior to 4.9.3.\nThe attack vector is network-based and exposes the application to remote attackers capable of delivering crafted malicious content via social engineering, phishing, or malicious web pages.\nNo authentication or specific privileges are required on the part of the attacker to construct the malicious request payload, though the victim must be targeted via browser-based interaction.\nThe step-by-step attack flow proceeds as follows: First, the attacker provisions and controls a specific user account within the targeted WordPress installation.\nSecond, the attacker crafts a malicious HTML page or script containing an automated submission—such as a forged form or an asynchronous JavaScript request—targeting the vulnerable authentication endpoint of the ShopEngine Elementor WooCommerce Builder Addon.\nThird, the attacker induces the victim to load this malicious resource via a crafted link or browsing activity.\nFourth, the victim's browser executes the request, dispatching authentication parameters that forcefully log the victim into the attacker-controlled account on the target WordPress site without the victim's knowledge or consent.\nFifth, unaware of the session switch, the victim proceeds to the checkout page and inputs sensitive personal information, including billing addresses and shipping details.\nFinally, because the active session belongs to the attacker, the submitted checkout data is persistently stored within the attacker's account database records.\nThe post-exploitation impact allows the attacker to retrieve and read the victim's confidential billing and shipping data directly from their account interface, leading to a significant breach of user privacy and data integrity."
}
CVE-2026-19088: ShopEngine CSRF Account Login Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere