What is CVE-2026-19088?
CVE-2026-19088 is a CSRF (Cross-Site Request Forgery) vulnerability in the ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before version 4.9.3. The flaw in an unprotected authentication endpoint allows an attacker to log a victim into an attacker-controlled account, potentially stealing billing and shipping details entered during checkout. Immediate update to version 4.9.3 or later is required.
Azərbaycanca: CVE-2026-19088, ShopEngine Elementor WooCommerce Builder Addon WordPress plaginində 4.9.3 versiyasından əvvəlki versiyalarda CSRF (Cross-Site Request Forgery) zəifliyidir. Bu zəiflik autentifikasiya endpointlərindən birinin qorunmaması səbəbindən təcavüzkara qurbanı özünün idarə etdiyi hesaba daxil etməyə imkan verir, nəticədə qurbanın ödəniş zamanı daxil etdiyi faktura və çatdırılma məlumatları oğurlana bilər. Plagini dərhal 4.9.3 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ1
What is the nature of the CVE-2026-19088 vulnerability related to the ShopEngine plugin?
CVE-2026-19088 is a CSRF vulnerability in the ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before version 4.9.3. The flaw in an unprotected authentication endpoint allows an attacker to log a victim into an attacker-controlled account, potentially stealing billing and shipping details entered during checkout.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.