CVE-2026-7655Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-11); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-11: 2Mentions · 2026-07-13: 1Mentions · 2026-07-15: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-07-15: 1Technical Details · 2026-07-11: 2Technical Details · 2026-07-13: 1Technical Details · 2026-07-15: 107-1107-1307-15
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-112
Disclosure2
2026-07-131
Disclosure1
2026-07-151
Disclosure1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-7655 - Privilege Escalation via account takeover in #SureCart plugin for #WordPress. #CVSS 8.1. Unauthenticated attackers can change admin email addresses. No patch available. Update now. #CVEAlert #devsecops #devops #developers #sysadmin #infosec #git #github #gitlab

    Post summary

    The tweet announces CVE-2026-7655, a privilege escalation vulnerability in the SureCart WordPress plugin with CVSS 8.1, noting that no patch is currently available.

    1001071
    978 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-7655 - Privilege Escalation via account takeover in SureCart plugin for WordPress. CVSS 8.1. Unauthenticated attackers can change admin email addresses. No patch available. Update now. #CVE #WordPress #infosec #devsecops #developers #github #gitlab #git. https://www.valtersit.com/cve/CVE-2026-7655

    Post summary

    Valtersit.com announces CVE‑2026‑7655, a privilege‑escalation flaw in the SureCart WordPress plugin that lets unauthenticated attackers change admin emails; the vulnerability scores 8.1 and no patch is yet available.

    0000052
    979 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7655 The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not prop… https://www.cve.org/CVERecord?id=CVE-2026-7655 ----- Traducción: CVE-2026-7655 El … http://infoflow.cloud`

    Post summary

    The text announces the CVE-2026-7655, describing a privilege escalation vulnerability in SureCart plugin up to version 4.2.3.

    0000042
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7655 The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not prop… https://www.cve.org/CVERecord?id=CVE-2026-7655

    Post summary

    CVE-2026-7655 exposes a privilege‑escalation vulnerability in the SureCart WordPress plugin (v4.2.3 and earlier), enabling account takeover; the post lacks information on PoC, exploit code, active attacks, or patches.

    00000393
    57.8K followersView on X

Explore more