Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75971— ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes

Quick assessment

Affected
roxnor ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution 是适用于 WordPress 的一款插件,该插件存在权限提升漏洞。在 4.9.4 及以下版本中,由于 函数被注册到 WordPress 核心 操作钩子上,且缺乏插件自有的能力检查以及白名单过滤机制,导致攻击者提供的 WXR 导入文件中的任意 名称/值对被直接传递给 函数。这使得具有 Shop Manager 级别访问权限及以上的用户可以写入任意的 Word

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75971

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes
Source: CVE Program / CVE List V5
Vulnerability Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, causing arbitrary `<wp_option>` name/value pairs parsed from an attacker-supplied WXR import file to be passed directly to `update_option()`. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover. This is exploitable by Shop Manager-level users because WooCommerce grants that role the `import` capability, allowing it to reach the WordPress Importer flow that fires the `import_start` hook on which `rum_importer()` is registered, contrary to the assumption that the hook is restricted to Administrators.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

II. Public POCs for CVE-2026-75971

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75971

登录查看更多情报信息。

Patches & Fixes for CVE-2026-75971 (1)

Vendor Advisories for CVE-2026-75971 (1)

Other References for CVE-2026-75971 (2)

Same Patch Batch · roxnor · 2026-08-25 · 4 CVEs total

CVE-2026-76063 6.4 MEDIUM FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_fea
CVE-2026-18100 6.4 MEDIUM MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_i
CVE-2026-75930 4.3 MEDIUM FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post

IV. Related Vulnerabilities

V. Comments for CVE-2026-75971

No comments yet


Leave a comment