Sceawere
Vulnerability Detail
CVE-2026-97245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SureCart Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- SureCart
- Product
- SureCart
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:36.433Z",
"pubdate": "2026-09-30T13:17:36.433Z",
"executiveSummary": "This vulnerability is identified as a privilege escalation flaw affecting the SureCart plugin for WordPress in versions 4.7.2 and below.\nThe vulnerability originates from improper access control validation within the plugin's internal authorization logic, which fails to correctly restrict capabilities assigned to the 'Shop Worker' user role.\nSuccessful exploitation allows an authenticated user with the 'Shop Worker' role to escalate their privileges beyond the intended scope, potentially gaining administrative access or performing unauthorized actions within the WordPress environment.\nThe risk implication is critical, as it undermines the principle of least privilege, enabling malicious actors to manipulate store configurations, access sensitive customer data, or execute administrative functions.\nExploitation requires the attacker to have an existing, low-privileged 'Shop Worker' account. No complex network interception is required, as the vulnerability resides within the application's core request processing logic.\nThis flaw presents a significant security risk to e-commerce platforms utilizing SureCart, necessitating immediate remediation to maintain site integrity and protect against unauthorized privilege escalation.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of capability checks within the SureCart plugin's REST API endpoints and internal action handlers. Specifically, the plugin fails to enforce strict authorization verification when processing requests submitted by users assigned the 'Shop Worker' role.\nIn WordPress environments, the 'Shop Worker' role is intended to have limited access, typically restricted to managing specific order-related tasks. However, in the vulnerable versions (4.7.2 and below), the application logic relies on insufficient capability validation mechanisms. Instead of verifying specific granular capabilities via the WordPress current_user_can() function, the code improperly assumes that certain administrative actions are safe to execute if the user is merely authenticated as a store-related user.\nThe attack flow begins with an authenticated attacker possessing the 'Shop Worker' role. The attacker crafts a request targeting specific administrative-only endpoints or protected functions intended for store administrators. Because the plugin's authorization middleware fails to validate if the user possesses the required 'manage_options' or 'administrator' level capabilities before executing the requested method, the server proceeds to process the request as if it were an authorized administrator.\nThis failure in the authorization layer allows the attacker to perform several unauthorized operations, including but not limited to: modifying plugin settings, accessing restricted customer order data, changing payment gateway configurations, or potentially injecting malicious scripts via configurable input fields that lack sufficient sanitization for non-admin roles.\nThe vulnerable component exists within the SureCart REST API controllers, where request dispatching logic fails to cross-reference the user's role-based access control (RBAC) definitions against the sensitivity of the requested operation. The vulnerability is persistent and requires authenticated access; however, it does not depend on specific external network conditions, as it is a logic flaw inherent to the plugin's code structure.\nPost-exploitation impact is severe, as the attacker can achieve persistent unauthorized access, escalate to full site administrative control, or exfiltrate sensitive data. Since the exploit triggers legitimate administrative functions within the WordPress API, the unauthorized actions may appear indistinguishable from legitimate administrative activity in standard system logs, complicating incident response and forensic analysis efforts."
}