THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18480 (HIGH 8.8) — The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and

[NVD] CVE-2026-18480 (HIGH 8.8) — The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and

mednvdPublished 2026-09-06

CVE-2026-18480 CVSS: 8.8 HIGH Published: 2026-09-06T07:16:43.097

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It furth

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18480