What the vulnerability does
01Description
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it possible for authenticated attackers, with Editor-level access and above, to activate and deactivate licenses.
Explanation of Vulnerability in Simple Terms
02Summary
ShopEngine Elementor WooCommerce Builder Addon versions up to 4.8.4 contain an authorization flaw that allows high-privilege users to make unintended modifications. The vulnerability requires administrator-level access and does not expose sensitive data or disrupt site availability. Site owners should update to a version newer than 4.8.4 when available.
What an attacker can do
03Attacker Capabilities
A high-privilege user can make unauthorized modifications to site data.
Potential impact on your site
04Site Impact
Admins with compromised credentials could alter site content or settings beyond their intended scope.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
October 25, 2025
CVE published
April 8, 2026
Record updated