Privilege Escalation in ShopEngine WooCommerce Builder Addon for WordPress
CVE-2026-75971
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-75971?
The ShopEngine Elementor WooCommerce Builder Addon for WordPress is susceptible to a Privilege Escalation vulnerability affecting all versions up to 4.9.4. The issue arises from the rum_importer() function, which is improperly registered on the import_start action hook without a proper capability check or allowlist filtering. This oversight allows authenticated users with Shop Manager permissions or higher to exploit the import function, enabling modifications to critical WordPress options. By manipulating an attacker-supplied WXR import file, these users could, for instance, set users_can_register to 1 and change default_role to administrator. This capability leads to unauthorized self-registration of Administrator accounts, posing a significant risk of complete site compromise.
Affected Version(s)
ShopEngine Elementor WooCommerce Builder Addon β All in One WooCommerce Solution with eCommerce Templates & Woo Widgets 0 <= 4.9.4