PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28005 Nexcess CVE debrief

CVE-2026-28005 is a critical unauthenticated privilege escalation vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. This vulnerability allows attackers to potentially gain elevated privileges, impacting administrators and users of the plugin. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity. Evidence is limited, and further verification is needed.

Vendor
Nexcess
Product
Kadence WooCommerce Email Designer
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Administrators and users of Kadence WooCommerce Email Designer plugin versions <= 1.5.19 should prioritize remediation. This includes reviewing and applying vendor patches, monitoring for suspicious activity, and implementing compensating controls where necessary. Security teams, vulnerability management teams, and operators of affected systems should also be aware of the potential impact and take steps to mitigate the vulnerability.

Technical summary

CVE-2026-28005 is a critical vulnerability (CVSS Score: 9.8) in Kadence WooCommerce Email Designer plugin versions <= 1.5.19, allowing unauthenticated privilege escalation. This vulnerability impacts administrators and users of the plugin, potentially allowing attackers to gain elevated privileges. Affected product deployments should be identified, and defenders should review official advisories and monitor for suspicious activity.

Defensive priority

Immediate attention recommended due to critical severity and potential for unauthenticated privilege escalation.

Recommended defensive actions

  • Inventory and version checks for Kadence WooCommerce Email Designer plugin
  • Apply vendor remediation or patches if available
  • Monitor for suspicious activity
  • Implement compensating controls
  • Review official advisories for mitigation guidance

Evidence notes

Evidence is limited; primary official records indicate a critical vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. Further verification needed. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then.