Critical Vulnerability in WooCommerce Plugin CVE-2026-28005
This text was generated using artificial intelligence (AI).On August 6, 2026, the security provider Patchstack reported a critical vulnerability in the WordPress plugin Kadence WooCommerce Email Designer. The gap is identified by the identifier CVE-2026-28005 was conducted and, according to Patchstack, received a rating of 9.8 (Critical) according to the CVSS standard. It allows attackers to escalate privileges without prior authentication (Unauthenticated Privilege Escalation), enabling them to gain administrative control over affected e-commerce websites.
Security Update: Not available at the time of publication
Technical Analysis of CVE-2026-28005
According to the Advisory from Patchstack all versions of the plugin up to and including 1.5.19 Affected. The vulnerability allows an unauthenticated attacker to elevate their privileges to those of an administrator. Such an attack can be carried out remotely and without any interaction from the website operator.
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H describes the risk in detail:
AV:N (Attack Vector: Network): The attack can be carried out over the Internet.
AC:L (Attack Complexity: Low): No complex preparations are necessary to use it.
PR:N (Privileges Required: None): The attacker does not need any login credentials or existing permissions.
A successful attack would have far-reaching consequences for the confidentiality, integrity, and availability of the affected systems. Attackers with administrator privileges could access sensitive customer data, manipulate order processes, or use the website as a launching pad for further attacks.
Assessment of the Source Situation and Recurring Risks
As of this publication, Patchstack is the only publicly known source for this vulnerability. As of press time, CVE-2026-28005 had not yet been listed in the National Vulnerability Database (NVD) or on MITRE, which may indicate that the CVE ID has been newly reserved and the publication process is still ongoing. For security teams, this means that systems that rely exclusively on curated feeds may not yet detect this threat.
The situation points to a pattern: In August 2025, with CVE-2025-54697 (CVSS 7.2, High) A previous vulnerability in the same plugin was patched (fixed in version 1.5.17). However, that vulnerability required Shop Manager authentication—CVE-2026-28005 is therefore significantly more severe, as it can be exploited without any authentication. The repeated occurrence of critical vulnerabilities in the same component underscores the need for continuous monitoring of third-party software.
Recommendations for Operators
Since no security patch is available yet, proactive protective measures are necessary. Companies using the plugin should consider the following steps:
Identification: Determine on which WordPress instances the plugin Kadence WooCommerce Email Designer is installed and check which version is being used.
Risk Mitigation: If you are using a vulnerable version (<= 1.5.19), the safest course of action is to immediately disable the plugin until the developer releases an update.
Temporary measures: If disabling the system would critically disrupt business processes, using a Web Application Firewall (WAF) with specific rules to block suspicious requests can serve as a temporary solution. However, this is no substitute for an update.
Operators of e-commerce stores in the EU that process customers’ personal data should also determine whether a successful exploitation of this vulnerability would trigger a reporting obligation under GDPR Art. 33 triggers: In the event of a data breach that poses a risk to data subjects, there is a 72-hour deadline for reporting the breach to the competent data protection authority. For companies that fall under the NIS-2 Directive In addition, entities that fall under this category—such as e-commerce operators classified as essential or critical infrastructure—are required to demonstrate that they have implemented appropriate technical measures to reduce their attack surface.
Vulnerability Management for Third-Party Software
The Vulnerability CVE-2026-28005 highlights a key challenge in IT security: the lack of transparency regarding third-party software components in use. Every plugin, every library, and every external service expands a company’s digital attack surface—and often remains in the blind spot of internal asset management.
LocateRisk helps companies achieve this transparency. As part of the External Attack Surface Management (EASM) All externally accessible IT systems—including web applications such as WordPress instances with their installed plugins—are continuously identified and analyzed for known vulnerability patterns. This inventory serves as the basis for quickly assessing your own exposure to new vulnerability reports, such as CVE-2026-28005, without having to rely on manual assessments.
This approach complements the Vendor Risk Management (VRM): A technical review of the software components in use enables a fact-based risk assessment that goes beyond mere self-reported information from suppliers. LocateRisk is operated in German data centers and helps companies incorporate requirements related to data residency and the U.S. CLOUD Act into their risk assessments.
CVE-2026-28005 is a critical vulnerability (CVSS 9.8) in the WordPress plugin Kadence WooCommerce Email Designer. It allows an unauthenticated attacker to elevate their privileges to the administrator level and thereby gain full control over an affected WordPress installation.
All versions of the plugin up to and including 1.5.19 are affected. As of the publication of this article, no security patch was available. Administrators should disable the plugin until an update is released and the Patchstack Advisory Monitor for updates.
The safest course of action is to immediately disable the plugin on all affected WordPress installations. As a temporary workaround, a Web Application Firewall (WAF) with specific rules to block suspicious requests can be used. However, it is not a substitute for a vendor patch and should only be used as a stopgap measure until an official update is released.
As of August 6, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.