cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forshopengine shopengine

Direction: ascending
Jun 06, 2024

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2022-45371

CVE, Research URL

CVE-2022-45371

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.
Affected versions
max 4.1.2.
Status
vulnerable
Oct 11, 2025

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2025-10173

CVE, Research URL

CVE-2025-10173

Date
Sep 26, 2025
Research Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings.
Affected versions
max 4.8.4.
Status
vulnerable
Nov 10, 2025

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2025-11888

CVE, Research URL

CVE-2025-11888

Date
Oct 25, 2025
Research Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.
Affected versions
max 4.8.5.
Status
vulnerable
Dec 10, 2025

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2025-12358

CVE, Research URL

CVE-2025-12358

Date
Dec 03, 2025
Research Description
The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes it possible for unauthenticated attackers to add or remove products from a user's wishlist via a forged request granted they can trick a site's user into performing an action such as clicking on a link.
Affected versions
max 4.8.6.
Status
vulnerable
Aug 15, 2026

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2026-19088

CVE, Research URL

CVE-2026-19088

Date
Aug 13, 2026
Research Description
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Affected versions
max 4.9.3.
Status
vulnerable
Aug 26, 2026

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2026-75971

CVE, Research URL

CVE-2026-75971

Date
Aug 25, 2026
Research Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, causing arbitrary `<wp_option>` name/value pairs parsed from an attacker-supplied WXR import file to be passed directly to `update_option()`. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover. This is exploitable by Shop Manager-level users because WooCommerce grants that role the `import` capability, allowing it to reach the WordPress Importer flow that fires the `import_start` hook on which `rum_importer()` is registered, contrary to the assumption that the hook is restricted to Administrators.
Affected versions
max 4.9.5.
Status
vulnerable
Sep 15, 2026

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution # CVE-2026-85575

CVE, Research URL

CVE-2026-85575

Date
Sep 15, 2026
Research Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 4.9.6.
Status
vulnerable