Sceawere
Vulnerability Detail
CVE-2026-28005UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kadence WooCommerce Email Designer Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Nexcess
- Product
- Kadence WooCommerce Email Designer
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-06T15:16:51.560Z",
"pubdate": "2026-08-06T15:16:51.560Z",
"executiveSummary": "An unauthenticated privilege escalation vulnerability has been identified in the Kadence WooCommerce Email Designer plugin for WordPress, specifically affecting versions 1.5.19 and below.\nThis security flaw allows remote, unauthenticated threat actors to manipulate privilege levels or perform unauthorized administrative actions by leveraging improper access controls within the affected plugin endpoints.\nThe impact of this vulnerability is critical, as successful exploitation may grant attackers unauthorized administrative access, compromising the entire WordPress installation, altering transactional email templates, or executing further malicious operations against the underlying application.\nThe affected product is the Kadence WooCommerce Email Designer plugin.\nThe risk implication involves complete system compromise due to the acquisition of elevated privileges without requiring prior authentication or valid credentials.\nAttacker capabilities include unauthenticated remote exploitation over the network, bypassing standard authentication barriers to interact with vulnerable functions exposed by the plugin.\nNo complex exploitation requirements are specified beyond network accessibility to the targeted WordPress instance running vulnerable versions of the software.",
"technicalDetails": "The root cause of the vulnerability stems from improper access control enforcement within the Kadence WooCommerce Email Designer plugin for versions 1.5.19 and prior.\nSpecifically, the vulnerable component fails to adequately validate whether incoming requests originate from authenticated users possessing administrative privileges before executing sensitive functionality.\nThe vulnerability is exposed over the network via HTTP/HTTPS protocols, allowing remote attackers to interact directly with insecurely implemented AJAX actions, REST API endpoints, or form submission handlers defined within the plugin codebase.\nAuthentication requirements are entirely absent, permitting unauthenticated actors to trigger restricted execution flows that should otherwise be strictly guarded behind capability checks such as manage_options.\nPrivilege requirements are nonexistent for the attacker during the initial phase of the attack vector, yet the resultant post-exploitation impact achieves elevated or administrative privileges within the WordPress environment.\nThe exploitation method involves crafting specialized HTTP requests directed at the vulnerable endpoints exposed by the Kadence WooCommerce Email Designer plugin.\nThe attack flow proceeds as follows: First, the unauthenticated attacker identifies the target WordPress instance running a vulnerable version (<= 1.5.19) of the Kadence WooCommerce Email Designer plugin. Second, the attacker formulates an HTTP request targeting the improperly secured function handlers within the plugin. Third, due to the lack of adequate nonce validation and capability checks, the application processes the request as if it were executed by a legitimate administrator. Finally, the execution flow grants the attacker elevated privileges or performs unauthorized modifications, leading to full application compromise.\nPayload behavior during this process typically involves injecting parameters designed to manipulate user roles, create new administrative accounts, or alter critical plugin configurations.\nThe post-exploitation impact includes unauthorized administrative access, persistence mechanisms via newly created rogue accounts, potential data exfiltration, and the ability to inject malicious payloads into WooCommerce transactional emails sent to customers."
}