CVE-2026-19088: Unknown Shopengine Elementor Woocommerce Builder Addon
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Affected products
- Unknown Shopengine Elementor Woocommerce Builder Addon: before 4.9.3 (fixed in 4.9.3)
Published 2026-08-13. Last modified 2026-08-26.