Executive brief
ShopEngine is a popular WordPress plugin that adds WooCommerce product building features to Elementor. The plugin's import function fails to properly validate user permissions and imported options, allowing Shop Manager-level users to modify critical WordPress settings. An attacker with Shop Manager access can enable user self-registration and set new administrators, leading to complete site takeover.
Technical details
The vulnerability exists in the `rum_importer()` function, which is registered on the WordPress `import_start` action hook without proper capability checks or allowlist validation. The function directly passes arbitrary WordPress option names and values from attacker-supplied WXR (WordPress eXtended RSS) import files to `update_option()`. Although the hook is designed for Administrators, Shop Manager-level users can reach it because WooCommerce grants that role the `import` capability. An authenticated Shop Manager can exploit this to set `users_can_register` to `1` and `default_role` to `administrator`, enabling open self-registration of admin accounts. The vulnerability affects all versions up to and including 4.9.4; patch status and remediation details should be verified with the plugin maintainers.
Affected products
- ShopEngine Elementor WooCommerce Builder up to and including 4.9.4
Timeline
- 2026-08-25: disclosed