Junglewise Threat Intelligence

CVE-2026-7655: SureCart WordPress plugin privilege escalation via account takeover

CVE-2026-7655 · Severity: high · CVSS 8.1 · Published 2026-07-11

Executive brief

SureCart, a popular e-commerce plugin for WordPress, contains a security flaw that could allow unauthorized individuals to take over user accounts. By exploiting a weakness in how the plugin syncs customer data, an attacker could change the email address associated with an account, including those of site administrators. Once the email is changed, the attacker can use standard password reset tools to gain full control of the website, potentially leading to data theft or complete site disruption.

Technical details

The SureCart plugin for WordPress is vulnerable to an account takeover and privilege escalation flaw due to insufficient identity validation during customer profile synchronization from webhook events. Specifically, the plugin fails to properly verify a user's identity before updating sensitive details like email addresses. An unauthenticated attacker who knows a target's customer ID can trigger a webhook event to change the email address of a linked WordPress user, including administrators. Once the email is updated, the attacker can initiate a standard WordPress password reset to gain full access to the account. This vulnerability is addressed in versions following 4.2.3.

Affected products

  • surecart SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments up to, and including, 4.2.3

Timeline

  • 2026-07-11: advisory: NVD and Wordfence published the advisory.
  • 2026-07-11: disclosed

References

Related threats