Extension WordPress
Vulnérabilités Ecwid by Lightspeed Ecommerce Shopping Cart
Cette page rassemble les failles publiées pour Ecwid by Lightspeed Ecommerce Shopping Cart, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ecwid by Lightspeed Ecommerce Shopping Cart
13 fiches
Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 – Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it…
*-7.0.7
7.0.8
14/02/2026
Ecwid Shopping Cart <= 7.0.5 – Missing Authorization
The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access…
*-7.0.5
7.0.6
19/01/2026
Ecwid Shopping Cart <= 7.0.6 – Missing Authorization
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated…
*-7.0.6
7.0.7
12/01/2026
Ecwid Shopping Cart <= 7.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-7.0
7.0.1
04/04/2025
Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 – Cross-Site Request Forgery to Send Deactivation Message
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This…
*-6.12.27
6.12.28
17/02/2025
Ecwid Ecommerce Shopping Cart <= 6.12.10 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-6.12.10
6.12.11
29/03/2024
Ecwid Ecommerce Shopping Cart <= 6.12.4 – Cross-Site Request Forgery
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php.…
*-6.12.4
6.12.5
28/11/2023
Ecwid Ecommerce Shopping Cart <= 6.12.3 – Missing Authorization on multiple functions
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it…
*-6.12.3
6.12.4
07/11/2023
Ecwid Shopping Cart <= 6.11.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-6.11.4
6.11.5
17/03/2023
Ecwid Ecommerce Shopping Cart <= 6.11.3 – Cross Site Request Forgery
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.11.3. This is due to missing or incorrect nonce validation on the do_woo_import() function. This makes it possible…
*-6.11.3
6.11.4
27/01/2023
Ecwid Ecommerce Shopping Cart <= 6.10.23 – Cross-Site Request Forgery to Settings/Options Update
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible…
*-6.10.23
6.10.24
11/07/2022
Ecwid Ecommerce Shopping Cart <= 6.10.22 – Insufficient Access Control on Multiple AJAX Actions
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product…
*-6.10.22
6.10.23
09/07/2022
Ecwid Ecommerce Shopping Cart <= 4.4.3 – Unauthenticated PHP Object injection
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to…
*-4.4.3
4.4.4
08/08/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.