Critical Vulnerabilities in WordPress Plugins (CVE-2026-28005, CVE-2026-6235)
This text was generated using artificial intelligence (AI).Update August 8, 2026: In addition, CVE-2026-6235 (CVSS 9.8) was discovered in the Sendmachine for WordPress plugin. This vulnerability also allows unauthenticated privilege escalation. See below for details.
On August 6, 2026, the security provider Patchstack reported a critical vulnerability in the WordPress plugin Kadence WooCommerce Email Designer. The gap is identified by the identifier CVE-2026-28005 was conducted and, according to Patchstack, received a rating of 9.8 (Critical) according to the CVSS standard. It allows attackers to escalate privileges without prior authentication (Unauthenticated Privilege Escalation), enabling them to gain administrative control over affected e-commerce websites.
Security Update: Not available for CVE-2026-28005 at the time of publication; patch status unknown for CVE-2026-6235
Technical Analysis of CVE-2026-28005
According to the Advisory from Patchstack all versions of the plugin up to and including 1.5.19 Affected. The vulnerability allows an unauthenticated attacker to elevate their privileges to those of an administrator. Such an attack can be carried out remotely and without any interaction from the website operator.
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H describes the risk in detail:
AV:N (Attack Vector: Network): The attack can be carried out over the Internet.
AC:L (Attack Complexity: Low): No complex preparations are necessary to use it.
PR:N (Privileges Required: None): The attacker does not need any login credentials or existing permissions.
A successful attack would have far-reaching consequences for the confidentiality, integrity, and availability of the affected systems. Attackers with administrator privileges could access sensitive customer data, manipulate order processes, or use the website as a launching pad for further attacks.
Technical Analysis of CVE-2026-6235
According to the Advisory from Wordfence CVE-2026-6235 affects the plugin Sendmachine for WordPress in all versions up to and including 1.0.20. The vulnerability lies in the function manage_admin_requests and enables an authorization bypass attack.
The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H is identical to CVE-2026-28005 and describes a similar risk profile:
AV:N (Attack Vector: Network): An attack via the Internet is possible.
AC:L (Attack Complexity: Low): No complex preparations are required.
PR:N (Privileges Required: None): No authentication required.
The vulnerability allows an unauthenticated attacker to bypass authorization checks and execute administrative functions. This can lead to the complete compromise of the affected WordPress instance, including the ability to manipulate content, access user data, or inject malicious code.
Assessment of the Source Situation and Recurring Risks
As of this publication, Patchstack is the only publicly known source for CVE-2026-28005. Wordfence has issued an advisory for CVE-2026-6235. As of press time, neither CVE had been listed in the National Vulnerability Database (NVD) or on MITRE, which may indicate that the CVE IDs were newly reserved and the publication process is still ongoing. For security teams, this means that systems relying exclusively on curated feeds may not yet detect these threats.
The situation points to a pattern: In August 2025, with CVE-2025-54697 (CVSS 7.2, High) A previous vulnerability in the Kadence plugin was patched (fixed in version 1.5.17). However, that vulnerability required Shop Manager authentication—CVE-2026-28005 is therefore significantly more severe, as it can be exploited without any authentication. The repeated occurrence of critical vulnerabilities in WordPress plugins underscores the need for continuous monitoring of third-party software.
Recommendations for Operators
Since no security patch is yet available for CVE-2026-28005 and the patch status for CVE-2026-6235 is unknown, proactive protective measures are necessary. Organizations using any of the affected plugins should consider the following steps:
Identification: Determine on which WordPress instances the plugins Kadence WooCommerce Email Designer or Sendmachine for WordPress are installed and check the versions being used.
Risk Mitigation: If you are using a vulnerable version (Kadence <= May 1, 2019, Sendmachine <= 1.0.20), the safest course of action is to immediately disable the plugin in question until the manufacturer releases an update.
Temporary measures: If disabling the system would critically disrupt business processes, using a Web Application Firewall (WAF) with specific rules to block suspicious requests can serve as a temporary solution. However, this is no substitute for an update.
Operators of e-commerce stores in the EU that process customers’ personal data should also determine whether a successful exploitation of these vulnerabilities would trigger a reporting obligation under GDPR Art. 33 triggers: In the event of a data breach that poses a risk to data subjects, there is a 72-hour deadline for reporting the breach to the competent data protection authority. For companies that fall under the NIS-2 Directive In addition, entities that fall under this category—such as e-commerce operators classified as essential or critical infrastructure—are required to demonstrate that they have implemented appropriate technical measures to reduce their attack surface.
Vulnerability Management for Third-Party Software
The Vulnerabilities CVE-2026-28005 and CVE-2026-6235 highlight a key challenge in IT security: the lack of transparency regarding third-party software components in use. Every plugin, every library, and every external service expands a company’s digital attack surface—and often remains in the blind spot of internal asset management.
LocateRisk helps companies achieve this transparency. As part of the External Attack Surface Management (EASM) All externally accessible IT systems—including web applications such as WordPress instances with their installed plugins—are continuously identified and analyzed for known vulnerability patterns. This inventory serves as the basis for quickly assessing your own exposure to new vulnerability reports, such as CVE-2026-28005 or CVE-2026-6235, without having to rely on manual assessments.
This approach complements the Vendor Risk Management (VRM): A technical review of the software components in use enables a fact-based risk assessment that goes beyond mere self-reported information from suppliers. LocateRisk is operated in German data centers and helps companies incorporate requirements related to data residency and the U.S. CLOUD Act into their risk assessments.
CVE-2026-28005 is a critical vulnerability (CVSS 9.8) in the WordPress plugin Kadence WooCommerce Email Designer. CVE-2026-6235 is another critical vulnerability (CVSS 9.8) in the Sendmachine for WordPress plugin. Both vulnerabilities allow an unauthenticated attacker to elevate their privileges to the administrator level and thereby gain full control over an affected WordPress installation.
For Kadence WooCommerce Email Designer all versions up to and including 1.5.19 affected. As of the publication of this article, no security patch was available. For Sendmachine for WordPress all versions up to and including 1.0.20 Affected; the patch status is unknown. Administrators should disable the affected plugins until updates are available and monitor the advisories for updates.
The safest course of action is to immediately deactivate the affected plugins on all WordPress installations. As a temporary workaround, a Web Application Firewall (WAF) with specific rules to block suspicious requests can be used. However, it is not a substitute for a vendor patch and should only be used as a stopgap measure until official updates are released.
As of August 8, 2026. This post is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.