CVSS
N/A
CVSS
EPSS
N/A
Exploit Prediction Score
Published
August 13, 2026
Exploitability
No EPSS data available
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
No CWE data available.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).