Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Feb 14, 2026

Ecwid by Lightspeed Ecommerce Shopping Cart Vulnerabilities

Review known vulnerability records for the WordPress plugin Ecwid by Lightspeed Ecommerce Shopping Cart (`ecwid-shopping-cart`), including severity, CVE references, affected versions, and patch status.

Known Records
13
High or Critical
3
Linked CVEs
10
Last Updated
Feb 15, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Ecwid by Lightspeed Ecommerce Shopping Cart so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
13 records include a published patch path.
Severity Mix
1 critical and 2 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Ecwid by Lightspeed Ecommerce Shopping Cart

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-1750
Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenti...

Published
Feb 14, 2026
Patched Release
7.0.8
Affected Versions
Versions up to 7.0.7
Next Step
Update to 7.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24580
Ecwid Shopping Cart <= 7.0.5 - Missing Authorization

The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an una...

Published
Jan 19, 2026
Patched Release
7.0.6
Affected Versions
Versions up to 7.0.5
Next Step
Update to 7.0.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24613
Ecwid Shopping Cart <= 7.0.6 - Missing Authorization

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized a...

Published
Jan 12, 2026
Patched Release
7.0.7
Affected Versions
Versions up to 7.0.6
Next Step
Update to 7.0.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-32195
Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

Published
Apr 04, 2025
Patched Release
7.0.1
Affected Versions
Versions up to 7.0
Next Step
Update to 7.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13795
Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible...

Published
Feb 17, 2025
Patched Release
6.12.28
Affected Versions
Versions up to 6.12.27
Next Step
Update to 6.12.28 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2456
Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Published
Mar 29, 2024
Patched Release
6.12.11
Affected Versions
Versions up to 6.12.10
Next Step
Update to 6.12.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-51533
Ecwid Ecommerce Shopping Cart <= 6.12.4 - Cross-Site Request Forgery

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. T...

Published
Nov 28, 2023
Patched Release
6.12.5
Affected Versions
Versions up to 6.12.4
Next Step
Update to 6.12.5 or newer if supported.
Plugin Medium Patched: Yes
Ecwid Ecommerce Shopping Cart <= 6.12.3 - Missing Authorization on multiple functions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to...

Published
Nov 07, 2023
Patched Release
6.12.4
Affected Versions
Versions up to 6.12.3
Next Step
Update to 6.12.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24408
Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

Published
Mar 17, 2023
Patched Release
6.11.5
Affected Versions
Versions up to 6.11.4
Next Step
Update to 6.11.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24377
Ecwid Ecommerce Shopping Cart <= 6.11.3 - Cross Site Request Forgery

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.11.3. This is due to missing or incorrect nonce validation on the do_woo_import() function. This makes it possible for unauthenticated attackers...

Published
Jan 27, 2023
Patched Release
6.11.4
Affected Versions
Versions up to 6.11.3
Next Step
Update to 6.11.4 or newer if supported.
Plugin High Patched: Yes CVE-2022-2432
Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticate...

Published
Jul 11, 2022
Patched Release
6.10.24
Affected Versions
Versions up to 6.10.23
Next Step
Update to 6.10.24 or newer if supported.
Plugin Medium Patched: Yes
Ecwid Ecommerce Shopping Cart <= 6.10.22 - Insufficient Access Control on Multiple AJAX Actions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category page...

Published
Jul 09, 2022
Patched Release
6.10.23
Affected Versions
Versions up to 6.10.22
Next Step
Update to 6.10.23 or newer if supported.