Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18480— SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover

Quick assessment

Affected
Unknown SureCart
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SureCart WordPress 插件在 4.6.3 版本之前,未能确保受客户更新影响的账户与权限检查所授权的账户一致。这使得拥有“订阅者”权限级别账户的用户可以更改其他用户(包括管理员)的电子邮件地址,并通过密码重置功能接管该账户。此外,攻击者可以控制客户记录并将其与任意用户关联,同时向任何已认证用户泄露客户标识符和电子邮件地址。这些漏洞组合在一起,使得仅凭一个订阅者级别的账户即可实现账户接管。

AI Predicted 8.2 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18480

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover
Source: CVE Program / CVE List V5
Vulnerability Description
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown SureCart 4.0.0 ~ 4.6.3 -

II. Public POCs for CVE-2026-18480

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18480

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18480 (1)

Same Patch Batch · Unknown · 2026-09-06 · 6 CVEs total

CVE-2026-85038 B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati
CVE-2026-84219 Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding
CVE-2026-75793 SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login
CVE-2026-84028 Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin
CVE-2026-13159 Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation

IV. Related Vulnerabilities

V. Comments for CVE-2026-18480

No comments yet


Leave a comment