CVE-2026-28005: pre-auth privilege escalation in Nexcess Kadence WooCommerce Email Designer

Attackers can escalate privileges on the Kadence WooCommerce Email Designer WordPress plugin without logging in, allowing remote code or configuration changes; this vulnerability is tracked as CVE-2026-28005. Versions 1.5.19 and earlier on the 1.x branch are affected. Exploitation requires only network access to a site that has the vulnerable plugin installed and does not require user interaction or an authenticated account, per the vulnerability data and CVSS vector.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00483
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a remote, unauthenticated privilege-escalation (no login required) that can lead to full compromise of affected sites, so isolate internet-facing installs and prioritize mitigation until a vendor update is available.

What is CVE-2026-28005?

Attackers can escalate privileges on the Kadence WooCommerce Email Designer WordPress plugin without logging in, allowing remote code or configuration changes; this vulnerability is tracked as CVE-2026-28005. Versions 1.5.19 and earlier on the 1.x branch are affected. Exploitation requires only network access to a site that has the vulnerable plugin installed and does not require user interaction or an authenticated account, per the vulnerability data and CVSS vector.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Nexcess Kadence WooCommerce Email Designer are affected?

BRANCHAFFECTEDFIXED
1.x1.5.19 and earlier

Is CVE-2026-28005 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-28005

  1. Remove or deactivate the Kadence WooCommerce Email Designer plugin on exposed sites until a patched release is available.
  2. Restrict access to WordPress admin interfaces (IP allowlists, WAF rules) to limit remote attack surface.
  3. Monitor logs and integrity of plugin and site files for unexpected changes and signs of compromise.
  4. Apply the vendor's official guidance and install the vendor-supplied patch as soon as a fixed version is released.

Frequently asked questions

Is CVE-2026-28005 being actively exploited?

There are no public reports of exploitation of CVE-2026-28005 as of 2026-09-29.

Which Kadence WooCommerce Email Designer versions are affected by CVE-2026-28005?

Kadence WooCommerce Email Designer versions 1.5.19 and earlier on the 1.x branch are listed as affected by CVE-2026-28005.

Is there a patch for CVE-2026-28005?

No fixed version is reported in the available data; a patch is not listed, so follow vendor guidance and apply mitigations until a vendor update is published.

Does CVE-2026-28005 require authentication?

No, CVE-2026-28005 does not require authentication; the vulnerability allows unauthenticated remote privilege escalation against the Kadence WooCommerce Email Designer plugin.

References