DIRAS TAKE
Urgent: this is a remote, unauthenticated privilege-escalation (no login required) that can lead to full compromise of affected sites, so isolate internet-facing installs and prioritize mitigation until a vendor update is available.
What is CVE-2026-28005?
Attackers can escalate privileges on the Kadence WooCommerce Email Designer WordPress plugin without logging in, allowing remote code or configuration changes; this vulnerability is tracked as CVE-2026-28005. Versions 1.5.19 and earlier on the 1.x branch are affected. Exploitation requires only network access to a site that has the vulnerable plugin installed and does not require user interaction or an authenticated account, per the vulnerability data and CVSS vector.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Nexcess Kadence WooCommerce Email Designer are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.5.19 and earlier |
Is CVE-2026-28005 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-28005
- Remove or deactivate the Kadence WooCommerce Email Designer plugin on exposed sites until a patched release is available.
- Restrict access to WordPress admin interfaces (IP allowlists, WAF rules) to limit remote attack surface.
- Monitor logs and integrity of plugin and site files for unexpected changes and signs of compromise.
- Apply the vendor's official guidance and install the vendor-supplied patch as soon as a fixed version is released.
Frequently asked questions
Is CVE-2026-28005 being actively exploited?
There are no public reports of exploitation of CVE-2026-28005 as of 2026-09-29.
Which Kadence WooCommerce Email Designer versions are affected by CVE-2026-28005?
Kadence WooCommerce Email Designer versions 1.5.19 and earlier on the 1.x branch are listed as affected by CVE-2026-28005.
Is there a patch for CVE-2026-28005?
No fixed version is reported in the available data; a patch is not listed, so follow vendor guidance and apply mitigations until a vendor update is published.
Does CVE-2026-28005 require authentication?
No, CVE-2026-28005 does not require authentication; the vulnerability allows unauthenticated remote privilege escalation against the Kadence WooCommerce Email Designer plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28005
- cve.org/CVERecord?id=CVE-2026-28005
- patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-privilege-escalation-vulnerability?_s_id=cve
- All Nexcess CVEs on CVE Radar
- CVEs published in September 2026