Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-28005: Kadence WooCommerce Email Designer plugin <= 1.5.19 - Unauthenticated access to sensitive data

CVE-2026-28005 · published 1 month ago
Summary

An outdated version of the Kadence WooCommerce Email Designer plugin on your WordPress site can allow unauthorized users to access sensitive data. This is a security risk because it can lead to unauthorized changes to your site's settings. Update the plugin to the latest version to fix this issue.

What to do
  • Update nexcess kadence woocommerce email designer to version 1.5.19.1.
Affected software
VendorProductAffected versions
nexcess kadence woocommerce email designer <= 1.5.19
Fix: upgrade to 1.5.19.1
Original advisory text
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published6 Aug 2026
Updated27 Sep 2026
First seen6 Aug 2026
Sources
CVE-2026-28005 · MITRE
Track software like this
Free during beta