Junglewise Threat Intelligence

CVE-2026-17553: WP EasyCart privilege escalation via AJAX handler

CVE-2026-17553 · Severity: high · CVSS 7.2 · Published 2026-09-09

Executive brief

WP EasyCart is a widely-used e-commerce plugin for WordPress that manages online stores and product catalogs. A flaw in the plugin's settings handler allows Store Manager-level employees to escalate their privileges to administrator by manipulating WordPress configuration options, enabling them to create admin accounts and gain full control of the website.

Technical details

The vulnerability exists in the ec_ajax_save_page_default_options() AJAX handler, which accepts any $_POST key and passes it directly to update_option() without validation or allowlisting. The handler checks for 'manage_options' OR 'wpec_manager' capability; the built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options'. Authenticated attackers with Store Manager access (or higher) can leverage nonces emitted on frontend product/category templates to craft a POST request that updates critical WordPress options (e.g., default_role='administrator', users_can_register='1'). With registration enabled and default role set to admin, the attacker can self-register a new administrator account, achieving full site compromise. A patch is expected to implement an option allowlist.

Affected products

  • WP EasyCart WP EasyCart up to and including 5.9.3

Timeline

  • 2026-09-09: disclosed

References

Related threats