CVE-2026-19088 PUBLISHED

ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication

Assigner: WPScan
Reserved: 06.08.2026 Published: 13.08.2026 Updated: 13.08.2026

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.

Product Status

Vendor Unknown
Product ShopEngine Elementor WooCommerce Builder Addon
Versions Default: unaffected
  • affected from 0 to 4.9.3 (excl.)

Credits

  • Farid Narimanov finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE