Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Missing Authorization
medium
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 7.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.0.9
- Fixed in:
- 7.0.9
- Disclosed:
- Aug 14, 2026
CVE-2026-14332 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access
high
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permission...
- CVSS:
- 8.8
- Affected:
- up to 7.0.7
- Fixed in:
- 7.0.8
- Disclosed:
- Feb 14, 2026
CVE-2026-1750 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.8 - Subscriber+ Privilege Escalation
critical
- Affected:
- up to 7.0.8
- Fixed in:
- 7.0.8
- Disclosed:
- Feb 14, 2026
CVE-2026-1750 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] <= 7.0.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.
- Affected:
- up to 7.0.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24613 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] <= 7.0.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.
- Affected:
- up to 7.0.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24580 on NVD →
Ecwid Shopping Cart <= 7.0.5 - Missing Authorization
medium
The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.0.5
- Fixed in:
- 7.0.6
- Disclosed:
- Jan 19, 2026
CVE-2026-24580 on NVD →
Ecwid Shopping Cart < 7.0.6 - Missing Authorization
medium
- Affected:
- up to 7.0.6
- Fixed in:
- 7.0.6
- Disclosed:
- Jan 19, 2026
CVE-2026-24580 on NVD →
Ecwid Shopping Cart <= 7.0.6 - Missing Authorization
medium
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 7.0.6
- Fixed in:
- 7.0.7
- Disclosed:
- Jan 12, 2026
CVE-2026-24613 on NVD →
Ecwid Shopping Cart < 7.0.7 - Missing Authorization
medium
- Affected:
- up to 7.0.7
- Fixed in:
- 7.0.7
- Disclosed:
- Jan 12, 2026
CVE-2026-24613 on NVD →
Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 7.0
- Fixed in:
- 7.0.1
- Disclosed:
- Apr 4, 2025
CVE-2025-32195 on NVD →
Ecwid Shopping Cart < 7.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Apr 4, 2025
CVE-2025-32195 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart allows Stored XSS. This issue affects Ecwid Shopping Cart: from n/a through 7.0.
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.1
- Disclosed:
- Apr 4, 2025
CVE-2025-32195 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28
unknown
[en] The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to s...
- Affected:
- up to 6.12.28
- Fixed in:
- 6.12.28
- Disclosed:
- Feb 18, 2025
CVE-2024-13795 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message
medium
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send d...
- CVSS:
- 4.3
- Affected:
- up to 6.12.27
- Fixed in:
- 6.12.28
- Disclosed:
- Feb 17, 2025
CVE-2024-13795 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart < 6.12.28 - Cross-Site Request Forgery to Send Deactivation Message
medium
- Affected:
- up to 6.12.28
- Fixed in:
- 6.12.28
- Disclosed:
- Feb 17, 2025
CVE-2024-13795 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11
unknown
[en] The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...
- Affected:
- up to 6.12.11
- Fixed in:
- 6.12.11
- Disclosed:
- Apr 9, 2024
CVE-2024-2456 on NVD →
Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...
- CVSS:
- 6.4
- Affected:
- up to 6.12.10
- Fixed in:
- 6.12.11
- Disclosed:
- Mar 29, 2024
CVE-2024-2456 on NVD →
Ecwid Ecommerce Shopping Cart < 6.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
medium
- Affected:
- up to 6.12.11
- Fixed in:
- 6.12.11
- Disclosed:
- Mar 29, 2024
CVE-2024-2456 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.
- Affected:
- up to 6.12.5
- Fixed in:
- 6.12.5
- Disclosed:
- Feb 28, 2024
CVE-2023-51533 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5
unknown
[en] The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- Affected:
- up to 6.12.5
- Fixed in:
- 6.12.5
- Disclosed:
- Jan 16, 2024
CVE-2023-6292 on NVD →
Ecwid Ecommerce Shopping Cart <= 6.12.4 - Cross-Site Request Forgery
medium
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticate...
- CVSS:
- 4.3
- Affected:
- up to 6.12.4
- Fixed in:
- 6.12.5
- Disclosed:
- Nov 28, 2023
CVE-2023-51533 on NVD →
Ecwid Ecommerce Shopping Cart < 6.12.5 - Cross-Site Request Forgery
medium
- Affected:
- up to 6.12.5
- Fixed in:
- 6.12.5
- Disclosed:
- Nov 28, 2023
CVE-2023-51533 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5
unknown
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticate...
- Affected:
- up to 6.12.5
- Fixed in:
- 6.12.5
- Disclosed:
- Nov 28, 2023
Ecwid Ecommerce Shopping Cart < 6.12.5 - Arbitrary Plugin Settings Change via CSRF
medium
- Affected:
- up to 6.12.5
- Fixed in:
- 6.12.5
- Disclosed:
- Nov 21, 2023
CVE-2023-6292 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4
unknown
Update the WordPress Ecwid Shopping Cart plugin to the latest available version (at least 6.12.4).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress Ecwid Shopping Cart Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a f...
- Affected:
- up to 6.12.4
- Fixed in:
- 6.12.4
- Disclosed:
- Nov 9, 2023
Ecwid Ecommerce Shopping Cart <= 6.12.3 - Missing Authorization on multiple functions
medium
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.
- CVSS:
- 5.4
- Affected:
- up to 6.12.3
- Fixed in:
- 6.12.4
- Disclosed:
- Nov 7, 2023
Ecwid Ecommerce Shopping Cart < 6.12.4 - Missing Authorization on multiple functions
medium
- Affected:
- up to 6.12.4
- Fixed in:
- 6.12.4
- Disclosed:
- Nov 7, 2023
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4
unknown
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.
- Affected:
- up to 6.12.4
- Fixed in:
- 6.12.4
- Disclosed:
- Nov 7, 2023
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.5
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions.
- Affected:
- up to 6.11.5
- Fixed in:
- 6.11.5
- Disclosed:
- May 8, 2023
CVE-2023-24408 on NVD →
Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 6.11.4
- Fixed in:
- 6.11.5
- Disclosed:
- Mar 17, 2023
CVE-2023-24408 on NVD →
Ecwid Shopping Cart < 6.11.5 - Contributor+ Stored Cross-Site Scriping
unknown
- Affected:
- up to 6.11.5
- Fixed in:
- 6.11.5
- Disclosed:
- Mar 17, 2023
CVE-2023-24408 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
- Affected:
- up to 6.11.4
- Fixed in:
- 6.11.4
- Disclosed:
- Feb 14, 2023
CVE-2023-24377 on NVD →
Ecwid Ecommerce Shopping Cart <= 6.11.3 - Cross Site Request Forgery
medium
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.11.3. This is due to missing or incorrect nonce validation on the do_woo_import() function. This makes it possible for unauthenticated attackers to trigger an import of data from WooCom...
- CVSS:
- 4.3
- Affected:
- up to 6.11.3
- Fixed in:
- 6.11.4
- Disclosed:
- Jan 27, 2023
CVE-2023-24377 on NVD →
Ecwid Shopping Cart < 6.11.4 - Import via CSRF
medium
- Affected:
- up to 6.11.4
- Fixed in:
- 6.11.4
- Disclosed:
- Jan 27, 2023
CVE-2023-24377 on NVD →
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24
unknown
[en] The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin option...
- Affected:
- up to 6.10.24
- Fixed in:
- 6.10.24
- Disclosed:
- Sep 6, 2022
CVE-2022-2432 on NVD →
Ecwid Ecommerce Shopping Cart < 6.10.24 - Settings Update via CSRF
medium
- Affected:
- up to 6.10.24
- Fixed in:
- 6.10.24
- Disclosed:
- Aug 4, 2022
CVE-2022-2432 on NVD →
Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update
high
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options gra...
- CVSS:
- 8.8
- Affected:
- up to 6.10.23
- Fixed in:
- 6.10.24
- Disclosed:
- Jul 11, 2022
CVE-2022-2432 on NVD →
Ecwid Ecommerce Shopping Cart <= 6.10.22 - Insufficient Access Control on Multiple AJAX Actions
medium
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category pages as well as changing, publishing, and u...
- CVSS:
- 5.4
- Affected:
- up to 6.10.22
- Fixed in:
- 6.10.23
- Disclosed:
- Jul 9, 2022
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23
unknown
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category pages as well as changing, publishing, and u...
- Affected:
- up to 6.10.23
- Fixed in:
- 6.10.23
- Disclosed:
- Jul 9, 2022
Ecwid Shopping Cart < 6.10.23 - Insufficient Access Control
unknown
- Affected:
- up to 6.10.23
- Fixed in:
- 6.10.23
- Disclosed:
- Jul 9, 2022
Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object injection
critical
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is...
- CVSS:
- 9.8
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- Aug 8, 2016
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4
unknown
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is...
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- Aug 8, 2016
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4
unknown
Because of this vulnerability, attackers can execute arbitrary PHP code.
Update the plugin.
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- Aug 8, 2016
Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object Injection
critical
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- Aug 8, 2016
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23
unknown
The plugin does not have adequate authorisation in various AJAX actions, which could allow users with a role as low as Subscriber to call them and perform unauthorised actions, such as creating product and category pages, and editing the storefront page.
- Affected:
- up to 6.10.23
- Fixed in:
- 6.10.23
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4
unknown
The Ecwid Ecommerce Shopping Cart WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4
unknown
The plugin is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.
- Affected:
- up to 6.12.4
- Fixed in:
- 6.12.4