
CVE-2026-19088 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attac… https://www.cve.org/CVERecord?id=CVE-2026-19088
Post summary
The text discloses a CSRF vulnerability in the ShopEngine Elementor WooCommerce Builder WordPress plugin (versions < 4.9.3) that could allow attackers to exploit an unprotected authentication endpoint.
