CVE-2026-28005

Nexcess · Kadence WooCommerce Email Designer

The Kadence WooCommerce Email Designer plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to escalate privileges.

Executive summary

This critical privilege escalation vulnerability in the Kadence WooCommerce Email Designer plugin allows unauthenticated attackers to achieve full administrative control over the affected WordPress installation.

Vulnerability

The plugin fails to perform necessary capability checks, resulting in a CWE-862 Missing Authorization flaw. This allows an unauthenticated attacker to execute unauthorized actions, effectively bypassing security controls.

Business impact

A successful exploit grants an attacker administrative privileges, leading to complete site compromise, data theft, and potential malware distribution. Given the CVSS score of 9.8, this vulnerability represents an existential threat to the integrity and availability of the affected web application.

Remediation

Immediate Action: Update the Nexcess Kadence WooCommerce Email Designer plugin to version 1.5.19.1 or later immediately.

Proactive Monitoring: Review administrative user accounts for unauthorized creations or modifications and monitor server logs for suspicious POST requests targeting plugin endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized administrative requests and suspicious traffic patterns directed at the WordPress plugin directory.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability carries a critical severity rating and requires immediate attention from security teams. Organizations using this plugin must prioritize applying the vendor-provided patch to prevent unauthorized access and potential full system takeover.