CVE-2026-7655: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in surecart SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.
AI Analysis
Technical Summary
CVE-2026-7655 is a privilege escalation vulnerability in the SureCart WordPress plugin (versions <=4.2.3). The plugin fails to validate user identity before updating user details such as email during webhook-based customer profile synchronization. This flaw enables unauthenticated attackers who know a customer ID to change the email address associated with that user, including administrator accounts if linked, and subsequently reset the password to take over the account. The vulnerability is classified under CWE-640 (Weak Password Recovery Mechanism).
Potential Impact
Successful exploitation allows an unauthenticated attacker to change the email address of any user linked to a SureCart customer record, including administrators, enabling password reset and full account takeover. This leads to complete compromise of affected user accounts with confidentiality, integrity, and availability impacts rated high.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to webhook endpoints and monitor for suspicious activity related to customer profile synchronization. Avoid linking administrator accounts to SureCart customer records if possible.
CVE-2026-7655: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in surecart SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
Description
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.
CVSS v3.1
Score 8.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7655 is a privilege escalation vulnerability in the SureCart WordPress plugin (versions <=4.2.3). The plugin fails to validate user identity before updating user details such as email during webhook-based customer profile synchronization. This flaw enables unauthenticated attackers who know a customer ID to change the email address associated with that user, including administrator accounts if linked, and subsequently reset the password to take over the account. The vulnerability is classified under CWE-640 (Weak Password Recovery Mechanism).
Potential Impact
Successful exploitation allows an unauthenticated attacker to change the email address of any user linked to a SureCart customer record, including administrators, enabling password reset and full account takeover. This leads to complete compromise of affected user accounts with confidentiality, integrity, and availability impacts rated high.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to webhook endpoints and monitor for suspicious activity related to customer profile synchronization. Avoid linking administrator accounts to SureCart customer records if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-05-01T18:32:09.448Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a51d59b68715ace4339775f
Added to database: 07/11/2026, 05:33:15 UTC
Last enriched: 07/18/2026, 12:38:24 UTC
Last updated: 08/23/2026, 13:35:19 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.