Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Feb 14, 2026

Ecwid by Lightspeed Ecommerce Shopping Cart Vulnerabilities

Review known vulnerability records for the WordPress plugin Ecwid by Lightspeed Ecommerce Shopping Cart (`ecwid-shopping-cart`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-1750, CVE-2026-24580 and CVE-2026-24613, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
13
High or Critical
3
Patch Coverage
100%
Last Updated
Feb 15, 2026
Related Security Guides

Use these guides while reviewing Ecwid by Lightspeed Ecommerce Shopping Cart fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Ecwid by Lightspeed Ecommerce Shopping Cart remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
11
1. Match the Package
Confirm the installed WordPress plugin slug is ecwid-shopping-cart before acting on any CVE from this cluster.
2. Sort by Severity
Start with 3 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
13 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Ecwid by Lightspeed Ecommerce Shopping Cart CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2026-1750
Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) P...
Privilege Escalation Versions up to 7.0.7 7.0.8 CVSS 8.8
CVE-2022-2432
Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Op...
Cross-Site Request Forgery Versions up to 6.10.23 6.10.24 CVSS 8.8
CVE-2025-32195
Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin...
Stored Cross-Site Scripting Versions up to 7.0 7.0.1 CVSS 6.4
CVE-2024-2456
Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-...
Stored Cross-Site Scripting Versions up to 6.12.10 6.12.11 CVSS 6.4
CVE-2023-24408
Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scrip...
Stored Cross-Site Scripting Versions up to 6.11.4 6.11.5 CVSS 6.4
CVE-2026-24613
Ecwid Shopping Cart <= 7.0.6 - Missing Authorization
Vulnerability Versions up to 7.0.6 7.0.7 CVSS 5.3
CVE-2026-24580
Ecwid Shopping Cart <= 7.0.5 - Missing Authorization
Vulnerability Versions up to 7.0.5 7.0.6 CVSS 4.3
CVE-2024-13795
Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery...
Cross-Site Request Forgery Versions up to 6.12.27 6.12.28 CVSS 4.3
CVE-2026-1750 High 7.0.8
CVE-2026-1750 Ecwid by Lightspeed Ecommerce Shopping Cart Privilege Escalation

Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access

CVE-2022-2432 High 6.10.24
CVE-2022-2432 Ecwid by Lightspeed Ecommerce Shopping Cart Cross-Site Request Forgery

Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update

CVE-2025-32195 Medium 7.0.1
CVE-2025-32195 Ecwid by Lightspeed Ecommerce Shopping Cart Stored Cross-Site Scripting

Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-2456 Medium 6.12.11
CVE-2024-2456 Ecwid by Lightspeed Ecommerce Shopping Cart Stored Cross-Site Scripting

Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2023-24408 Medium 6.11.5
CVE-2023-24408 Ecwid by Lightspeed Ecommerce Shopping Cart Stored Cross-Site Scripting

Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2026-24613 Medium 7.0.7
CVE-2026-24613 Ecwid by Lightspeed Ecommerce Shopping Cart Vulnerability

Ecwid Shopping Cart <= 7.0.6 - Missing Authorization

CVE-2026-24580 Medium 7.0.6
CVE-2026-24580 Ecwid by Lightspeed Ecommerce Shopping Cart Vulnerability

Ecwid Shopping Cart <= 7.0.5 - Missing Authorization

CVE-2024-13795 Medium 6.12.28
CVE-2024-13795 Ecwid by Lightspeed Ecommerce Shopping Cart Cross-Site Request Forgery

Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Ecwid by Lightspeed Ecommerce Shopping Cart so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
13 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 2 high severity findings.
Recent CVEs
CVE-2026-1750, CVE-2026-24580 and CVE-2026-24613
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Ecwid by Lightspeed Ecommerce Shopping Cart

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-1750
CVE-2026-1750: Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenti...

Published
Feb 14, 2026
Patched Release
7.0.8
Affected Versions
Versions up to 7.0.7
Next Step
Update to 7.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24580
CVE-2026-24580: Ecwid Shopping Cart <= 7.0.5 - Missing Authorization

The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an una...

Published
Jan 19, 2026
Patched Release
7.0.6
Affected Versions
Versions up to 7.0.5
Next Step
Update to 7.0.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24613
CVE-2026-24613: Ecwid Shopping Cart <= 7.0.6 - Missing Authorization

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized a...

Published
Jan 12, 2026
Patched Release
7.0.7
Affected Versions
Versions up to 7.0.6
Next Step
Update to 7.0.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-32195
CVE-2025-32195: Ecwid Shopping Cart <= 7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

Published
Apr 04, 2025
Patched Release
7.0.1
Affected Versions
Versions up to 7.0
Next Step
Update to 7.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13795
CVE-2024-13795: Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible...

Published
Feb 17, 2025
Patched Release
6.12.28
Affected Versions
Versions up to 6.12.27
Next Step
Update to 6.12.28 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2456
CVE-2024-2456: Ecwid Ecommerce Shopping Cart <= 6.12.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Published
Mar 29, 2024
Patched Release
6.12.11
Affected Versions
Versions up to 6.12.10
Next Step
Update to 6.12.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-51533
CVE-2023-51533: Ecwid Ecommerce Shopping Cart <= 6.12.4 - Cross-Site Request Forgery

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. T...

Published
Nov 28, 2023
Patched Release
6.12.5
Affected Versions
Versions up to 6.12.4
Next Step
Update to 6.12.5 or newer if supported.
Plugin Medium Patched: Yes
Ecwid Ecommerce Shopping Cart <= 6.12.3 - Missing Authorization on multiple functions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to...

Published
Nov 07, 2023
Patched Release
6.12.4
Affected Versions
Versions up to 6.12.3
Next Step
Update to 6.12.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24408
CVE-2023-24408: Ecwid Shopping Cart <= 6.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

Published
Mar 17, 2023
Patched Release
6.11.5
Affected Versions
Versions up to 6.11.4
Next Step
Update to 6.11.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24377
CVE-2023-24377: Ecwid Ecommerce Shopping Cart <= 6.11.3 - Cross Site Request Forgery

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.11.3. This is due to missing or incorrect nonce validation on the do_woo_import() function. This makes it possible for unauthenticated attackers...

Published
Jan 27, 2023
Patched Release
6.11.4
Affected Versions
Versions up to 6.11.3
Next Step
Update to 6.11.4 or newer if supported.
Plugin High Patched: Yes CVE-2022-2432
CVE-2022-2432: Ecwid Ecommerce Shopping Cart <= 6.10.23 - Cross-Site Request Forgery to Settings/Options Update

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticate...

Published
Jul 11, 2022
Patched Release
6.10.24
Affected Versions
Versions up to 6.10.23
Next Step
Update to 6.10.24 or newer if supported.
Plugin Medium Patched: Yes
Ecwid Ecommerce Shopping Cart <= 6.10.22 - Insufficient Access Control on Multiple AJAX Actions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category page...

Published
Jul 09, 2022
Patched Release
6.10.23
Affected Versions
Versions up to 6.10.22
Next Step
Update to 6.10.23 or newer if supported.