plugin

Ecwid Shopping Cart Vulnerabilities

47 known security issues reported for the Ecwid Shopping Cart WordPress plugin. Most recent disclosed Aug 14, 2026.

3 critical 2 high 21 medium

Running Ecwid Shopping Cart on your site? Check whether your installed version is affected.

Scan your site free

Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Missing Authorization

medium

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 7.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 7.0.9
Fixed in:
7.0.9
Disclosed:
Aug 14, 2026

CVE-2026-14332 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access

high

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permission...

CVSS:
8.8
Affected:
up to 7.0.7
Fixed in:
7.0.8
Disclosed:
Feb 14, 2026

CVE-2026-1750 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.8 - Subscriber+ Privilege Escalation

critical
Affected:
up to 7.0.8
Fixed in:
7.0.8
Disclosed:
Feb 14, 2026

CVE-2026-1750 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] <= 7.0.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.

Affected:
up to 7.0.5
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24613 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] <= 7.0.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.

Affected:
up to 7.0.5
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24580 on NVD →

Ecwid Shopping Cart <= 7.0.5 - Missing Authorization

medium

The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 7.0.5
Fixed in:
7.0.6
Disclosed:
Jan 19, 2026

CVE-2026-24580 on NVD →

Ecwid Shopping Cart < 7.0.6 - Missing Authorization

medium
Affected:
up to 7.0.6
Fixed in:
7.0.6
Disclosed:
Jan 19, 2026

CVE-2026-24580 on NVD →

Ecwid Shopping Cart <= 7.0.6 - Missing Authorization

medium

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 7.0.6
Fixed in:
7.0.7
Disclosed:
Jan 12, 2026

CVE-2026-24613 on NVD →

Ecwid Shopping Cart < 7.0.7 - Missing Authorization

medium
Affected:
up to 7.0.7
Fixed in:
7.0.7
Disclosed:
Jan 12, 2026

CVE-2026-24613 on NVD →

Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 7.0
Fixed in:
7.0.1
Disclosed:
Apr 4, 2025

CVE-2025-32195 on NVD →

Ecwid Shopping Cart < 7.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium
Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Apr 4, 2025

CVE-2025-32195 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart allows Stored XSS. This issue affects Ecwid Shopping Cart: from n/a through 7.0.

Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Apr 4, 2025

CVE-2025-32195 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28

unknown

[en] The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to s...

Affected:
up to 6.12.28
Fixed in:
6.12.28
Disclosed:
Feb 18, 2025

CVE-2024-13795 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message

medium

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send d...

CVSS:
4.3
Affected:
up to 6.12.27
Fixed in:
6.12.28
Disclosed:
Feb 17, 2025

CVE-2024-13795 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart < 6.12.28 - Cross-Site Request Forgery to Send Deactivation Message

medium
Affected:
up to 6.12.28
Fixed in:
6.12.28
Disclosed:
Feb 17, 2025

CVE-2024-13795 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11

unknown

[en] The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

Affected:
up to 6.12.11
Fixed in:
6.12.11
Disclosed:
Apr 9, 2024

CVE-2024-2456 on NVD →

Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...

CVSS:
6.4
Affected:
up to 6.12.10
Fixed in:
6.12.11
Disclosed:
Mar 29, 2024

CVE-2024-2456 on NVD →

Ecwid Ecommerce Shopping Cart < 6.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium
Affected:
up to 6.12.11
Fixed in:
6.12.11
Disclosed:
Mar 29, 2024

CVE-2024-2456 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.

Affected:
up to 6.12.5
Fixed in:
6.12.5
Disclosed:
Feb 28, 2024

CVE-2023-51533 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5

unknown

[en] The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Affected:
up to 6.12.5
Fixed in:
6.12.5
Disclosed:
Jan 16, 2024

CVE-2023-6292 on NVD →

Ecwid Ecommerce Shopping Cart <= 6.12.4 - Cross-Site Request Forgery

medium

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticate...

CVSS:
4.3
Affected:
up to 6.12.4
Fixed in:
6.12.5
Disclosed:
Nov 28, 2023

CVE-2023-51533 on NVD →

Ecwid Ecommerce Shopping Cart < 6.12.5 - Cross-Site Request Forgery

medium
Affected:
up to 6.12.5
Fixed in:
6.12.5
Disclosed:
Nov 28, 2023

CVE-2023-51533 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5

unknown

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticate...

Affected:
up to 6.12.5
Fixed in:
6.12.5
Disclosed:
Nov 28, 2023

Ecwid Ecommerce Shopping Cart < 6.12.5 - Arbitrary Plugin Settings Change via CSRF

medium
Affected:
up to 6.12.5
Fixed in:
6.12.5
Disclosed:
Nov 21, 2023

CVE-2023-6292 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

unknown

Update the WordPress Ecwid Shopping Cart plugin to the latest available version (at least 6.12.4). Unknown discovered and reported this Broken Access Control vulnerability in WordPress Ecwid Shopping Cart Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a f...

Affected:
up to 6.12.4
Fixed in:
6.12.4
Disclosed:
Nov 9, 2023

Ecwid Ecommerce Shopping Cart <= 6.12.3 - Missing Authorization on multiple functions

medium

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.

CVSS:
5.4
Affected:
up to 6.12.3
Fixed in:
6.12.4
Disclosed:
Nov 7, 2023

Ecwid Ecommerce Shopping Cart < 6.12.4 - Missing Authorization on multiple functions

medium
Affected:
up to 6.12.4
Fixed in:
6.12.4
Disclosed:
Nov 7, 2023

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

unknown

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.

Affected:
up to 6.12.4
Fixed in:
6.12.4
Disclosed:
Nov 7, 2023

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.5

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions.

Affected:
up to 6.11.5
Fixed in:
6.11.5
Disclosed:
May 8, 2023

CVE-2023-24408 on NVD →

Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-lev...

CVSS:
6.4
Affected:
up to 6.11.4
Fixed in:
6.11.5
Disclosed:
Mar 17, 2023

CVE-2023-24408 on NVD →

Ecwid Shopping Cart < 6.11.5 - Contributor+ Stored Cross-Site Scriping

unknown
Affected:
up to 6.11.5
Fixed in:
6.11.5
Disclosed:
Mar 17, 2023

CVE-2023-24408 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.

Affected:
up to 6.11.4
Fixed in:
6.11.4
Disclosed:
Feb 14, 2023

CVE-2023-24377 on NVD →

Ecwid Ecommerce Shopping Cart <= 6.11.3 - Cross Site Request Forgery

medium

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.11.3. This is due to missing or incorrect nonce validation on the do_woo_import() function. This makes it possible for unauthenticated attackers to trigger an import of data from WooCom...

CVSS:
4.3
Affected:
up to 6.11.3
Fixed in:
6.11.4
Disclosed:
Jan 27, 2023

CVE-2023-24377 on NVD →

Ecwid Shopping Cart < 6.11.4 - Import via CSRF

medium
Affected:
up to 6.11.4
Fixed in:
6.11.4
Disclosed:
Jan 27, 2023

CVE-2023-24377 on NVD →

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24

unknown

[en] The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin option...

Affected:
up to 6.10.24
Fixed in:
6.10.24
Disclosed:
Sep 6, 2022

CVE-2022-2432 on NVD →

Ecwid Ecommerce Shopping Cart < 6.10.24 - Settings Update via CSRF

medium
Affected:
up to 6.10.24
Fixed in:
6.10.24
Disclosed:
Aug 4, 2022

CVE-2022-2432 on NVD →

Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update

high

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options gra...

CVSS:
8.8
Affected:
up to 6.10.23
Fixed in:
6.10.24
Disclosed:
Jul 11, 2022

CVE-2022-2432 on NVD →

Ecwid Ecommerce Shopping Cart <= 6.10.22 - Insufficient Access Control on Multiple AJAX Actions

medium

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category pages as well as changing, publishing, and u...

CVSS:
5.4
Affected:
up to 6.10.22
Fixed in:
6.10.23
Disclosed:
Jul 9, 2022

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23

unknown

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category pages as well as changing, publishing, and u...

Affected:
up to 6.10.23
Fixed in:
6.10.23
Disclosed:
Jul 9, 2022

Ecwid Shopping Cart < 6.10.23 - Insufficient Access Control

unknown
Affected:
up to 6.10.23
Fixed in:
6.10.23
Disclosed:
Jul 9, 2022

Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object injection

critical

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is...

CVSS:
9.8
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Aug 8, 2016

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

unknown

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is...

Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Aug 8, 2016

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

unknown

Because of this vulnerability, attackers can execute arbitrary PHP code. Update the plugin.

Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Aug 8, 2016

Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object Injection

critical
Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Aug 8, 2016

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23

unknown

The plugin does not have adequate authorisation in various AJAX actions, which could allow users with a role as low as Subscriber to call them and perform unauthorised actions, such as creating product and category pages, and editing the storefront page.

Affected:
up to 6.10.23
Fixed in:
6.10.23

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

unknown

The Ecwid Ecommerce Shopping Cart WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.

Affected:
up to 4.4.4
Fixed in:
4.4.4

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

unknown

The plugin is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.

Affected:
up to 6.12.4
Fixed in:
6.12.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database