ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes
high
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned...
- CVSS:
- 7.2
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.5
- Disclosed:
- Aug 24, 2026
CVE-2026-75971 on NVD →
ShopEngine <= 4.9.2 - Cross-Site Request Forgery
medium
The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.3
- Disclosed:
- Aug 11, 2026
CVE-2026-19088 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution [shopengine] < 4.8.6
unknown
[en] The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This m...
- Affected:
- up to 4.8.6
- Fixed in:
- 4.8.6
- Disclosed:
- Dec 3, 2025
CVE-2025-12358 on NVD →
ShopEngine <= 4.8.5 - Cross-Site Request Forgery to Wishlist Manipulation
medium
The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes...
- CVSS:
- 4.3
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.6
- Disclosed:
- Dec 2, 2025
CVE-2025-12358 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution [shopengine] < 4.8.5
unknown
[en] The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes i...
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Oct 25, 2025
CVE-2025-11888 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update
low
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it pos...
- CVSS:
- 2.7
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.5
- Disclosed:
- Oct 24, 2025
CVE-2025-11888 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update
low
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-lev...
- CVSS:
- 2.7
- Affected:
- up to 4.8.3
- Fixed in:
- 4.8.4
- Disclosed:
- Sep 25, 2025
CVE-2025-10173 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution [shopengine] < 4.1.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions.
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- May 25, 2023
CVE-2022-45371 on NVD →
ShopEngine <= 4.1.1 - Cross-Site Request Forgery via get_product
medium
The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.1. This is due to missing or incorrect nonce validation on the get_product function. This makes it possible for unauthenticated attackers to update product IDs via a forged request granted they can tric...
- CVSS:
- 5.4
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Apr 19, 2023
CVE-2022-45371 on NVD →
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution [shopengine] < 4.8.4
unknown
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.4
CVE-2025-10173 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database