PatchSiren cyber security CVE debrief
CVE-2026-28005 Nexcess CVE debrief
CVE-2026-28005 is a critical unauthenticated privilege escalation vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. This vulnerability allows attackers to potentially gain elevated privileges, impacting administrators and users of the plugin. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity. Evidence is limited, and further verification is needed.
- Vendor
- Nexcess
- Product
- Kadence WooCommerce Email Designer
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators and users of Kadence WooCommerce Email Designer plugin versions <= 1.5.19 should prioritize remediation. This includes reviewing and applying vendor patches, monitoring for suspicious activity, and implementing compensating controls where necessary. Security teams, vulnerability management teams, and operators of affected systems should also be aware of the potential impact and take steps to mitigate the vulnerability.
Technical summary
CVE-2026-28005 is a critical vulnerability (CVSS Score: 9.8) in Kadence WooCommerce Email Designer plugin versions <= 1.5.19, allowing unauthenticated privilege escalation. This vulnerability impacts administrators and users of the plugin, potentially allowing attackers to gain elevated privileges. Affected product deployments should be identified, and defenders should review official advisories and monitor for suspicious activity.
Defensive priority
Immediate attention recommended due to critical severity and potential for unauthenticated privilege escalation.
Recommended defensive actions
- Inventory and version checks for Kadence WooCommerce Email Designer plugin
- Apply vendor remediation or patches if available
- Monitor for suspicious activity
- Implement compensating controls
- Review official advisories for mitigation guidance
Evidence notes
Evidence is limited; primary official records indicate a critical vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. Further verification needed. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28005 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28005
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28005 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28005
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.