cleantalk
Vulnerabilities and Security Researches

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution, CVE-2026-19088

CVE, Research URL

CVE-2026-19088

Published on
Aug 13, 2026
Research Description
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Affected versions
max 4.9.3.
Status
vulnerable