CVE-2026-19088: ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19088?
CVE-2026-19088 has a risk score of 47.
How do I fix CVE-2026-19088?
To fix CVE-2026-19088, update the ShopEngine Elementor WooCommerce Builder Addon plugin to version 4.9.3 or later.
What type of vulnerability is CVE-2026-19088?
CVE-2026-19088 is a CSRF (Cross-Site Request Forgery) vulnerability.
What are the potential impacts of CVE-2026-19088?
CVE-2026-19088 could lead to unauthorized disclosure of customers' personal identifiable information (PII).
Who is affected by CVE-2026-19088?
CVE-2026-19088 affects users of the ShopEngine Elementor WooCommerce Builder Addon plugin prior to version 4.9.3.