External risk intelligence

Kadence WooCommerce Email Designer Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-28005

The vulnerability affects a WordPress plugin, which is a web application component. WordPress sites are frequently deployed as internet-facing web applications, making the plugin's functionality and its unauthenticated attack surface commonly reachable from the public internet.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability found in a widely used WordPress plugin for customizing WooCommerce emails. The issue allows unauthenticated attackers to potentially gain elevated privileges, which could have significant implications for data integrity and system control. The main concern is to confirm if this specific plugin is in use and exposed.

  • Unauthenticated privilege escalation in an email plugin.
  • Affects website data and administrative control.
  • Confirm usage and exposure to assess risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by reaching a specific feature within the Kadence WooCommerce Email Designer plugin. Successful exploitation allows the attacker to escalate their privileges within the affected system.

  • Requires no authentication to attack.
  • Triggers through a vulnerable plugin feature.
  • Allows unauthenticated privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to escalate their privileges within the Kadence WooCommerce Email Designer plugin. This could potentially lead to unauthorized modifications of plugin settings or actions, impacting the functionality of the email designer and the WooCommerce store it integrates with.

  • Plugin settings and functionality.
  • Unauthenticated network access.
  • Unauthorized administrative actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated privilege escalation vulnerability in Kadence WooCommerce Email Designer impacts systems running the affected plugin. The first step is for platform or application owners to identify all instances of this plugin, confirm exposure and business criticality, and then coordinate remediation with the vendor or apply necessary updates.

  • Application and platform owners should prioritize remediation.
  • Verify plugin instances and their exposure.
  • Plan and coordinate vendor-supported updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kadence WooCommerce Email Designer plugin?

This software is a WordPress extension designed to help store owners customize the appearance and content of automated WooCommerce notification emails. By integrating directly with WordPress, it provides a specialized interface to modify templates for order confirmations, shipping updates, and other customer communications without requiring custom code.

What does CVE-2026-28005 mean for system security?

This vulnerability is classified as Improper Authorization (CWE-862). It means the plugin fails to verify whether a user has permission to perform administrative actions. Because of this, an attacker can bypass standard security checks to gain elevated access, effectively granting them control they should not have within the application.

How is this privilege escalation triggered?

The issue is triggered when an attacker interacts with a specific, improperly secured function within the plugin over the network. It does not require the attacker to be logged into the website, nor does it rely on valid user credentials to initiate the attack. Simply having the affected version installed and reachable is enough to facilitate the exploit.

Why should I be concerned about this CVE?

Halo Surface Signal indicates this vulnerability is likely to be relevant because the plugin runs on WordPress, a platform typically deployed as an internet-facing application. Since the plugin's features are accessible from the public web, unauthorized parties could reach the vulnerable component without needing to cross internal network perimeters.

Do I need to update my WordPress installation immediately?

Your first step is to verify if your site runs Kadence WooCommerce Email Designer version 1.5.19 or earlier. If you find the plugin in your environment, assess its usage and consult the vendor's site for the latest security release. Coordinating a patch through your standard maintenance process is the recommended way to resolve the security gap.

References