PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75971 roxnor CVE debrief

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, causing arbitrary `<wp_option>` name/value pairs parsed from an attacker-supplied WXR import file to be passed directly to `update_option()`.

Vendor
roxnor
Product
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

Defenders responsible for WordPress installations with the ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin, particularly those with Shop Manager-level users, should assess exposure and prioritize verification.

Why it matters

CVE-2026-75971 allows authenticated attackers with Shop Manager-level access to escalate privileges and potentially take over a WordPress site by modifying arbitrary options.

  • Enabling open self-registration of Administrator accounts
  • Full site takeover through arbitrary WordPress option modification
  • Elevation of privileges for authenticated attackers with Shop Manager-level access

Technical summary

The `rum_importer()` function is registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, allowing arbitrary `<wp_option>` name/value pairs to be passed directly to `update_option()`. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover. The vulnerability allows authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options.

Defensive priority

Defenders should prioritize verifying exposure of ShopEngine Elementor WooCommerce Builder Addon versions up to 4.9.4 and assessing the role of Shop Manager-level users.

Recommended defensive actions

  • Verify exposure of ShopEngine Elementor WooCommerce Builder Addon versions up to 4.9.4
  • Assess the role of Shop Manager-level users
  • Restrict access to the WordPress Importer flow
  • Monitor for suspicious activity related to the `import_start` hook
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability allows authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75971 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75971

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75971 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75971

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.