PatchSiren cyber security CVE debrief
CVE-2026-75971 roxnor CVE debrief
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, causing arbitrary `<wp_option>` name/value pairs parsed from an attacker-supplied WXR import file to be passed directly to `update_option()`.
- Vendor
- roxnor
- Product
- ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for WordPress installations with the ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin, particularly those with Shop Manager-level users, should assess exposure and prioritize verification.
Why it matters
CVE-2026-75971 allows authenticated attackers with Shop Manager-level access to escalate privileges and potentially take over a WordPress site by modifying arbitrary options.
- Enabling open self-registration of Administrator accounts
- Full site takeover through arbitrary WordPress option modification
- Elevation of privileges for authenticated attackers with Shop Manager-level access
Technical summary
The `rum_importer()` function is registered on the WordPress core `import_start` action hook with no plugin-owned capability check and no allowlist filtering, allowing arbitrary `<wp_option>` name/value pairs to be passed directly to `update_option()`. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover. The vulnerability allows authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options.
Defensive priority
Defenders should prioritize verifying exposure of ShopEngine Elementor WooCommerce Builder Addon versions up to 4.9.4 and assessing the role of Shop Manager-level users.
Recommended defensive actions
- Verify exposure of ShopEngine Elementor WooCommerce Builder Addon versions up to 4.9.4
- Assess the role of Shop Manager-level users
- Restrict access to the WordPress Importer flow
- Monitor for suspicious activity related to the `import_start` hook
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability allows authenticated attackers, with Shop Manager-level access and above, to write arbitrary WordPress options — most critically setting `users_can_register` to `1` and `default_role` to `administrator` — enabling open self-registration of Administrator accounts and full site takeover.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75971 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75971
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75971 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75971
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/shopengine/tags/4.9.4/core/builders/base.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/shopengine/tags/4.9.4/core/export-import/import.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.