VYPR

ShopEngine Elementor WooCommerce Builder Addon

by WordPress

Source repositories

CVEs (7)

  • CVE-2026-75971HigAug 25, 2026
    risk 0.47cvss 7.2epss 0.01

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core…

  • CVE-2026-85575MedSep 15, 2026
    risk 0.35cvss 6.4epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and…

  • CVE-2026-19088MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then…

  • CVE-2021-24262MedMay 5, 2021
    risk 0.35cvss 5.4epss 0.01

    The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

  • CVE-2025-12358MedDec 3, 2025
    risk 0.21cvss 4.3epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions…

  • CVE-2025-10173LowSep 26, 2025
    risk 0.18cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible…

  • CVE-2025-11888LowOct 25, 2025
    risk 0.11cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up…