CVE-2026-97245: WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability
Published Sep 30, 2026
·Updated
Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
Affected Software
1 affected component
SureCart SureCart WordPress plugin<=4.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SureCart Pluginto a version that resolves this vulnerability.Fixed in 4.7.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges (PR:H). It is not described as exploitable by an unauthenticated or low-privileged user.
2
Which SureCart versions are affected?
SureCart versions 4.7.2 and earlier are identified as affected. The provided data does not identify a fixed version.
3
Can this vulnerability be exploited remotely without user interaction?
The vector is network-based (AV:N), requires low attack complexity (AC:L), and requires no user interaction (UI:N). Exploitation still requires high privileges.