The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 06:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-19088
Mitre link : CVE-2026-19088
CVE.ORG link : CVE-2026-19088
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
