Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 06 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 06 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Surecart
Surecart surecart Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-269 CWE-285 CWE-639 |
|
| Vendors & Products |
Surecart
Surecart surecart Wordpress Wordpress wordpress |
Sun, 06 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone. | |
| Title | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-06T10:45:10.273Z
Reserved: 2026-07-31T12:29:08.541Z
Link: CVE-2026-18480
Updated: 2026-09-06T10:38:11.314Z
Status : Received
Published: 2026-09-06T07:16:43.097
Modified: 2026-09-06T11:18:00.657
Link: CVE-2026-18480
No data.
OpenCVE Enrichment
Updated: 2026-09-06T07:30:03Z