Executive brief
SureCart is a popular e-commerce solution for WordPress websites. A security flaw in the plugin allows users with low-level access (such as contributors) to bypass intended security restrictions. This could lead to unauthorized access to sensitive information or administrative functions, potentially compromising customer data or store operations.
Technical details
The SureCart plugin for WordPress (versions up to and including 4.0.2) is vulnerable to broken access control due to missing authorization checks (CWE-862). An attacker authenticated with a low-privileged role, such as a 'Contributor', can exploit incorrectly configured security levels to perform actions or access data they are not authorized to see. The vulnerability is reachable over the network without user interaction. The issue is resolved in version 4.0.3.
Affected products
- SureCart SureCart <= 4.0.2
Timeline
- 2026-02-24: other: Vulnerability reported by researcher
- 2026-03-26: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published
- 2026-04-08: patched: Patch available in version 4.0.3