Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-28005: Kadence WooCommerce Email Designer plugin <= 1.5.19 - Unauthenticated access to sensitive data
CVE-2026-28005 · published 1 month ago
Summary
An outdated version of the Kadence WooCommerce Email Designer plugin on your WordPress site can allow unauthorized users to access sensitive data. This is a security risk because it can lead to unauthorized changes to your site's settings. Update the plugin to the latest version to fix this issue.
What to do
- Update nexcess kadence woocommerce email designer to version 1.5.19.1.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| nexcess | kadence woocommerce email designer |
<= 1.5.19 Fix: upgrade to 1.5.19.1
|
Original advisory text
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published6 Aug 2026
Updated27 Sep 2026
First seen6 Aug 2026
Track software like this
Free during beta