Extension WordPress

Vulnérabilités Ecwid by Lightspeed Ecommerce Shopping Cart

Cette page rassemble les failles publiées pour Ecwid by Lightspeed Ecommerce Shopping Cart, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
1Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Ecwid by Lightspeed Ecommerce Shopping Cart

13 fiches

CVE-2026-1750 Élevée · 8,8
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 – Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it…

Versions affectées

*-7.0.7

Correctif

7.0.8

Publication

14/02/2026

CVE-2025-32195 Moyenne · 6,4
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Shopping Cart <= 7.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-7.0

Correctif

7.0.1

Publication

04/04/2025

CVE-2024-13795 Moyenne · 4,3
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 – Cross-Site Request Forgery to Send Deactivation Message

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This…

Versions affectées

*-6.12.27

Correctif

6.12.28

Publication

17/02/2025

CVE-2024-2456 Moyenne · 6,4
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 6.12.10 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-6.12.10

Correctif

6.12.11

Publication

29/03/2024

CVE-2023-51533 Moyenne · 4,3
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 6.12.4 – Cross-Site Request Forgery

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php.…

Versions affectées

*-6.12.4

Correctif

6.12.5

Publication

28/11/2023

Vulnérabilité Moyenne · 5,4
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 6.12.3 – Missing Authorization on multiple functions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it…

Versions affectées

*-6.12.3

Correctif

6.12.4

Publication

07/11/2023

CVE-2023-24408 Moyenne · 6,4
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Shopping Cart <= 6.11.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-6.11.4

Correctif

6.11.5

Publication

17/03/2023

CVE-2022-2432 Élevée · 8,8
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 6.10.23 – Cross-Site Request Forgery to Settings/Options Update

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible…

Versions affectées

*-6.10.23

Correctif

6.10.24

Publication

11/07/2022

Vulnérabilité Moyenne · 5,4
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 6.10.22 – Insufficient Access Control on Multiple AJAX Actions

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product…

Versions affectées

*-6.10.22

Correctif

6.10.23

Publication

09/07/2022

Vulnérabilité Critique · 9,8
Ecwid by Lightspeed Ecommerce Shopping Cart

Ecwid Ecommerce Shopping Cart <= 4.4.3 – Unauthenticated PHP Object injection

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to…

Versions affectées

*-4.4.3

Correctif

4.4.4

Publication

08/08/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités