CVE-2026-7655: SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7655?
The severity of CVE-2026-7655 is high with a CVSS score of 8.1.
How do I fix CVE-2026-7655?
To fix CVE-2026-7655, update the SureCart plugin to version 4.2.4 or later.
What causes CVE-2026-7655?
CVE-2026-7655 is caused by the SureCart plugin not properly validating a user's identity during webhook updates.
Who is affected by CVE-2026-7655?
Users of SureCart versions up to and including 4.2.3 are affected by CVE-2026-7655.
What impact does CVE-2026-7655 have on systems?
CVE-2026-7655 allows unauthenticated attackers to perform account takeover, leading to unauthorized user detail changes.