VYPR

Ecwid by Lightspeed Ecommerce Shopping Cart

by WordPress

CVEs (3)

  • CVE-2026-1750HigFeb 15, 2026
    risk 0.50cvss 8.8epss 0.00

    The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for…

  • CVE-2026-14332MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront…

  • CVE-2024-13795MedFeb 18, 2025
    risk 0.28cvss 4.3epss 0.00

    The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it…