CVE-2026-39488: WordPress SureCart plugin <= 4.0.2 - Broken Access Control vulnerability
Published Apr 8, 2026
·Updated
Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.
Affected Software
1 affected component
SureCart SureCart (WordPress plugin)<=4.0.2
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39488?
CVE-2026-39488 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-39488?
To fix CVE-2026-39488, update SureCart to the latest version beyond 4.0.2.
3
What type of vulnerability is CVE-2026-39488?
CVE-2026-39488 is a Broken Access Control vulnerability in the SureCart WordPress plugin.
4
Which versions of SureCart are affected by CVE-2026-39488?
CVE-2026-39488 affects all versions of SureCart from n/a up to and including 4.0.2.
5
What could be the impact of exploiting CVE-2026-39488?
Exploiting CVE-2026-39488 may allow unauthorized access to sensitive data due to incorrectly configured access control security levels.