Skip to main content
HIGH

CVE-2026-17553

CVSS v3

7.2

HIGH

EPSS Score

0.4 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonc

Technical details

CVSS v3 Vector
3.1
Published
2026-09-09
Last Modified
2026-09-09

Frequently asked questions

What is CVE-2026-17553?

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and the required nonc

Is CVE-2026-17553 actively exploited?

Active exploitation of CVE-2026-17553 has not been confirmed. The EPSS score is 0.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-17553?

CVE-2026-17553 has a CVSS v3 base score of 7.2 (HIGH severity), with vector string 3.1.

Is CVE-2026-17553 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key