PatchSiren cyber security CVE debrief
CVE-2026-28005 Nexcess CVE debrief
CVE-2026-28005 is a critical unauthenticated privilege escalation vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. This vulnerability allows attackers to potentially gain elevated privileges, impacting administrators and users of the plugin. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity. Evidence is limited, and further verification is needed.
- Vendor
- Nexcess
- Product
- Kadence WooCommerce Email Designer
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators and users of Kadence WooCommerce Email Designer plugin versions <= 1.5.19 should prioritize remediation. This includes reviewing and applying vendor patches, monitoring for suspicious activity, and implementing compensating controls where necessary. Security teams, vulnerability management teams, and operators of affected systems should also be aware of the potential impact and take steps to mitigate the vulnerability.
Technical summary
CVE-2026-28005 is a critical vulnerability (CVSS Score: 9.8) in Kadence WooCommerce Email Designer plugin versions <= 1.5.19, allowing unauthenticated privilege escalation. This vulnerability impacts administrators and users of the plugin, potentially allowing attackers to gain elevated privileges. Affected product deployments should be identified, and defenders should review official advisories and monitor for suspicious activity.
Defensive priority
Immediate attention recommended due to critical severity and potential for unauthenticated privilege escalation.
Recommended defensive actions
- Inventory and version checks for Kadence WooCommerce Email Designer plugin
- Apply vendor remediation or patches if available
- Monitor for suspicious activity
- Implement compensating controls
- Review official advisories for mitigation guidance
Evidence notes
Evidence is limited; primary official records indicate a critical vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. Further verification needed. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity.
Official resources
-
CVE-2026-28005 CVE record
CVE.org
-
CVE-2026-28005 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then.