Privilege Escalation in ShopEngine WooCommerce Builder Addon for WordPress
CVE-2026-75971

7.2HIGH

What is CVE-2026-75971?

The ShopEngine Elementor WooCommerce Builder Addon for WordPress is susceptible to a Privilege Escalation vulnerability affecting all versions up to 4.9.4. The issue arises from the rum_importer() function, which is improperly registered on the import_start action hook without a proper capability check or allowlist filtering. This oversight allows authenticated users with Shop Manager permissions or higher to exploit the import function, enabling modifications to critical WordPress options. By manipulating an attacker-supplied WXR import file, these users could, for instance, set users_can_register to 1 and change default_role to administrator. This capability leads to unauthorized self-registration of Administrator accounts, posing a significant risk of complete site compromise.

Affected Version(s)

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets 0 <= 4.9.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.