plugin

Wp Easycart Vulnerabilities

46 known security issues reported for the Wp Easycart WordPress plugin. Most recent disclosed Jul 2, 2026.

7 high 16 medium

Running Wp Easycart on your site? Check whether your installed version is affected.

Scan your site free

Shopping Cart & eCommerce Store <= 5.9.1 - Authenticated (Contributor+) SQL Injection

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.5
Affected:
up to 5.9.1
Fixed in:
5.9.2
Disclosed:
Jul 2, 2026

CVE-2026-57765 on NVD →

EasyCart <= 5.8.13 - Authenticated (Contributor+) SQL Injection

medium

The EasyCart plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.8.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.5
Affected:
up to 5.8.13
Fixed in:
5.8.14
Disclosed:
Feb 27, 2026

CVE-2026-32422 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] <= 5.8.11 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11.

Affected:
up to 5.8.11
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-62997 on NVD →

EasyCart <= 5.8.11 - Unauthenticated Information Exposure

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.11. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 5.8.11
Fixed in:
5.8.12
Disclosed:
Dec 8, 2025

CVE-2025-62997 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.7.9 (closed)

unknown

[en] The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.

Affected:
up to 5.7.9
Fixed in:
5.7.9
Disclosed:
Jan 8, 2025

CVE-2024-12712 on NVD →

Shopping Cart & eCommerce Store <= 5.7.8 - Missing Authorization to Order Updates

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.

CVSS:
5.3
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Jan 7, 2025

CVE-2024-12712 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.7.3 (closed)

unknown

[en] The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

Affected:
up to 5.7.3
Fixed in:
5.7.3
Disclosed:
Aug 20, 2024

CVE-2024-7827 on NVD →

Shopping Cart & eCommerce Store <= 5.7.2 - Authenticated (Contributor+) SQL Injection via model_number Parameter

high

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...

CVSS:
8.8
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Aug 19, 2024

CVE-2024-7827 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.6.0 (closed)

unknown

[en] Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jun 11, 2024

CVE-2024-35667 on NVD →

WP EasyCart <= 5.5.19 - Missing Authorization

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.19. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.5.19
Fixed in:
5.6.0
Disclosed:
Jun 3, 2024

CVE-2024-35667 on NVD →

Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, address...

CVSS:
5.3
Affected:
up to 5.6.4
Fixed in:
5.6.5
Disclosed:
May 10, 2024

CVE-2024-4213 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.6.5 (closed)

unknown

[en] The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, ad...

Affected:
up to 5.6.5
Fixed in:
5.6.5
Disclosed:
May 10, 2024

CVE-2024-4213 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.6.0 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Apr 15, 2024

CVE-2024-32452 on NVD →

WP EasyCart <= 5.5.19 - Cross-Site Request Forgery

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.19. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they c...

CVSS:
4.3
Affected:
up to 5.5.19
Fixed in:
5.6.0
Disclosed:
Apr 12, 2024

CVE-2024-32452 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.6.4 (closed)

unknown

[en] The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 5.6.4
Fixed in:
5.6.4
Disclosed:
Apr 12, 2024

CVE-2024-3211 on NVD →

Shopping Cart & eCommerce Store <= 5.6.3 - Authenticated (Contributor+) SQL Injection

high

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
8.8
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Apr 11, 2024

CVE-2024-3211 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.11 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...

Affected:
up to 5.4.11
Fixed in:
5.4.11
Disclosed:
Jul 12, 2023

CVE-2023-3023 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible for unauthenticated attackers to delete products via a forged request granted...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2891 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possible for unauthenticated attackers to bulk delete products via a forged reque...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2892 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possible for unauthenticated attackers to deactivate products via a forged request...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2893 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenticated attackers to duplicate products via a forged request g...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2896 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forg...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2894 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.9 (closed)

unknown

[en] The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauthenticated attackers to bulk activate products via a forged r...

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jun 9, 2023

CVE-2023-2895 on NVD →

WP EasyCart <= 5.4.10 - Authenticated (Administrator+) SQL Injection via 'orderby'

high

The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacker...

CVSS:
7.2
Affected:
up to 5.4.10
Fixed in:
5.4.11
Disclosed:
Jun 8, 2023

CVE-2023-3023 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_delete_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possible for unauthenticated attackers to bulk delete products via a forged request gr...

CVSS:
6.5
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2892 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_delete_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they...

CVSS:
6.5
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2891 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_duplicate_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenticated attackers to duplicate products via a forged request grante...

CVSS:
4.3
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2896 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_activate_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauthenticated attackers to bulk activate products via a forged reques...

CVSS:
4.3
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2895 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_deactivate_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possible for unauthenticated attackers to deactivate products via a forged request gran...

CVSS:
4.3
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2893 on NVD →

WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_deactivate_product

medium

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forged re...

CVSS:
4.3
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
May 27, 2023

CVE-2023-2894 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.4.3 (closed)

unknown

[en] The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.

Affected:
up to 5.4.3
Fixed in:
5.4.3
Disclosed:
Apr 3, 2023

CVE-2023-1124 on NVD →

Shopping Cart & eCommerce Store <= 5.4.2 - Authenticated (Admin+) Local File Inclusion via import_file_url

high

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.2 via the import_file_url parameter. This allows authenticated attackers, with administrator-level permissions, to include and execute arbitrary files on the server, allowing the executio...

CVSS:
7.2
Affected:
up to 5.4.2
Fixed in:
5.4.3
Disclosed:
Mar 13, 2023

CVE-2023-1124 on NVD →

Shopping Cart & eCommerce Store <= 5.2.6 - Cross-Site Request Forgery

medium

The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the 'wp-easycart-submit-newsletter' function. This makes it possible for unauthenticated attackers to perform an unknown action granted they c...

CVSS:
6.3
Affected:
up to 5.2.6
Fixed in:
5.3.0
Disclosed:
Apr 15, 2022

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.3.0 (closed)

unknown

The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the 'wp-easycart-submit-newsletter' function. This makes it possible for unauthenticated attackers to perform an unknown action granted they c...

Affected:
up to 5.3.0
Fixed in:
5.3.0
Disclosed:
Apr 15, 2022

Shopping Cart & eCommerce Store <= 5.2.4 - Cross-Site Request Forgery to Settings Update

medium

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.4. This is due to missing or incorrect nonce validation on the 'ec_admin_ajax_save_design_settings' AJAX action. This makes it possible for unauthenticated attackers to change arbit...

CVSS:
6.5
Affected:
up to 5.2.4
Fixed in:
5.2.5
Disclosed:
Mar 28, 2022

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.2.5 (closed)

unknown

Arbitrary Design Settings Update via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress Shopping Cart & eCommerce Store plugin (versions <= 5.2.4).

Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Mar 28, 2022

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.2.5 (closed)

unknown

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.4. This is due to missing or incorrect nonce validation on the 'ec_admin_ajax_save_design_settings' AJAX action. This makes it possible for unauthenticated attackers to change arbit...

Affected:
up to 5.2.5
Fixed in:
5.2.5
Disclosed:
Mar 28, 2022

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.1.5 (closed)

unknown

[en] The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.

Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Aug 19, 2021

CVE-2021-34645 on NVD →

Shopping Cart & eCommerce Store <= 5.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.

CVSS:
8.8
Affected:
up to 5.1.0
Fixed in:
5.1.5
Disclosed:
Aug 18, 2021

CVE-2021-34645 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] >= 1.1.30 - <= 3.0.20 (closed)

unknown

[en] The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.

Affected:
1.1.30 – 3.0.20
Fixed in:
3.0.20
Disclosed:
Oct 6, 2017

CVE-2015-2673 on NVD →

EasyCart 1.1.30 - 3.0.20 - Privilege Escalation

high

The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.

CVSS:
8.8
Affected:
1.1.30 – 3.0.20
Fixed in:
3.0.21
Disclosed:
Feb 26, 2015

CVE-2015-2673 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 3.0.16 (closed)

unknown

[en] Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to t...

Affected:
up to 3.0.16
Fixed in:
3.0.16
Disclosed:
Jan 15, 2015

CVE-2014-9308 on NVD →

Shopping Cart & eCommerce Store < 3.0.16 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.16 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the f...

CVSS:
8.8
Affected:
up to 3.0.16
Fixed in:
3.0.16
Disclosed:
Jan 9, 2015

CVE-2014-9308 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 2.0.6 (closed)

unknown

[en] The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jul 11, 2014

CVE-2014-4942 on NVD →

EasyCart <= 2.0.5 - Sensitive Information Disclosure

medium

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

CVSS:
5.3
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
May 28, 2014

CVE-2014-4942 on NVD →

Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.2.5 (closed)

unknown

The plugin is lacking CSRF checks in various AJAX actions, such as ec_admin_ajax_save_design_settings, which could allow attackers to make a logged in admin update arbitrary settings

Affected:
up to 5.2.5
Fixed in:
5.2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database