CVE-2026-17553: Shopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action

Published Sep 9, 2026
·
Updated

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ecajaxsavepagedefaultoptions() AJAX handler iterating over every $POST key and passing it directly into updateoption() without any allowlist, while gating the handler only on 'manageoptions' OR the plugin's custom 'wpecmanager' capability. The plugin's built-in 'wpecstoremanager' role holds 'wpecmanager' but not 'manageoptions', and the required nonce is emitted on frontend product/category templates that render for any user with 'wpecmanager'. This makes it possible for authenticated attackers, with Store Manager-level access and above, to elevate their privileges to administrator by updating arbitrary WordPress options such as defaultrole='administrator' and userscanregister='1', then self-registering a new account that is assigned the administrator role.

Affected Software

1 affected component
WordPress WP EasyCart<=5.9.3

Event History

Sep 9, 2026
CVE Published
via MITRE·03:28 AM
Data Sourced
via MITRE·03:28 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

Authenticated users with the plugin's Store Manager-level access or higher are exposed. The built-in wpec_store_manager role has the wpec_manager capability required by the affected AJAX handler, even though it does not have WordPress's manage_options capability.

2

What does an attacker need to do to gain administrator access?

The attacker needs an authenticated Store Manager-level account and the required nonce, which is emitted on frontend product and category templates for users with wpec_manager. They can update arbitrary WordPress options, including enabling registration and setting the default role to administrator, then register a new administrator account.

3

Are standard Store Manager accounts affected, or only full WordPress administrators?

Standard WP EasyCart Store Manager accounts are affected because the built-in role includes wpec_manager. An attacker does not need the WordPress manage_options capability to reach the vulnerable handler.

4

How can administrators determine whether exploitation may have occurred?

Review WordPress option values for users_can_register being enabled and default_role being set to administrator, as these changes can be used to create an administrator account. Also review newly created accounts for unexpected administrator-role users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203