AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19088

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The ShopEngine Elementor WooCommerce Builder Addon for WordPress prior to version 4.9.3 is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate protection on its authentication endpoint. This flaw allows an attacker to log victims into a malicious account, potentially compromising sensitive billing and shipping information entered during checkout. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-19088
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
WordPress

Original NVD Description

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.