CVE-2026-7655

SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.


We have discovered 3,132 live websites that are affected by CVE-2026-7655.

Run a Free Instant Scan




Affected Software

Product  Surecart
Category Wordpress Plugins
Vulnerable Domains3,132 live websites (84% of Surecart install base)
Vulnerable Versions
  • from 0 through 4.2.3
Vulnerable Versions Count90 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-640 Weak Password Recovery Mechanism for Forgotten Password



Details

  • Published - Jul 11, 2026
  • Updated - Jul 15, 2026

Credits

  • Supakiad S. (m3ez) (finder)

Website Distribution by Country

Number of websites using CVE-2026-7655
United States1,157 websites



Germany285 websites
Cyprus240 websites
France200 websites
GB146 websites
India112 websites
Italy71 websites
Netherlands69 websites
Canada61 websites
Poland54 websites

Website Distribution by TLD

Number of websites using CVE-2026-7655
.com1,692 websites
.org229 websites
.fr104 websites
.net76 websites
.de76 websites
.co.uk65 websites
.nl62 websites
.it58 websites
.pl42 websites
.com.br40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-7655

Top websites that are affected by CVE-2026-7655. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*******.com United States**,***
*****************.net GB**,***
************************.***.au Australia**,***
******************.dk Denmark***,***
*************.ie United States***,***
***********.com GB***,***
**********.org United States***,***
*******.com United States***,***
************.com United States***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2026-7655 is Weak Password Recovery Mechanism for Forgotten Password in Surecart
A total of 3,132 websites have been identified as vulnerable to CVE-2026-7655, based on global website indexing conducted by WebTechSurvey.
The Surecart is affected by the CVE-2026-7655 vulnerability.
Surecart versions up to and including 4.2.3 are vulnerable to CVE-2026-7655.