Extension WordPress
Vulnérabilités Shopping Cart & eCommerce Store
Cette page rassemble les failles publiées pour Shopping Cart & eCommerce Store, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Shopping Cart & eCommerce Store
23 fiches
Shopping Cart & eCommerce Store <= 5.9.1 – Authenticated (Contributor+) SQL Injection
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-5.9.1
Non indiqué
02/07/2026
EasyCart <= 5.8.13 – Authenticated (Contributor+) SQL Injection
The EasyCart plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.8.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.8.13
5.8.14
27/02/2026
EasyCart <= 5.8.11 – Unauthenticated Information Exposure
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.11. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-5.8.11
5.8.12
08/12/2025
Shopping Cart & eCommerce Store <= 5.7.8 – Missing Authorization to Order Updates
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible…
*-5.7.8
5.7.9
07/01/2025
Shopping Cart & eCommerce Store <= 5.7.2 – Authenticated (Contributor+) SQL Injection via model_number Parameter
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack…
*-5.7.2
5.7.3
19/08/2024
WP EasyCart <= 5.5.19 – Missing Authorization
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.19. This makes it possible for unauthenticated attackers…
*-5.5.19
5.6.0
03/06/2024
Shopping Cart & eCommerce Store <= 5.6.4 – Sensitive Information Exposure
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive…
*-5.6.4
5.6.5
10/05/2024
WP EasyCart <= 5.5.19 – Cross-Site Request Forgery
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.19. This is due to missing or incorrect nonce validation on an unknown function. This makes…
*-5.5.19
5.6.0
12/04/2024
Shopping Cart & eCommerce Store <= 5.6.3 – Authenticated (Contributor+) SQL Injection
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied…
*-5.6.3
5.6.4
11/04/2024
WP EasyCart <= 5.4.10 – Authenticated (Administrator+) SQL Injection via 'orderby'
The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-5.4.10
5.4.11
08/06/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_delete_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_bulk_delete_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_bulk_deactivate_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_deactivate_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_duplicate_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
WP EasyCart <= 5.4.8 – Cross-Site Request Forgery via process_bulk_activate_product
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauthenticated…
*-5.4.8
5.4.9
27/05/2023
Shopping Cart & eCommerce Store <= 5.4.2 – Authenticated (Admin+) Local File Inclusion via import_file_url
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.2 via the import_file_url parameter. This allows authenticated attackers, with administrator-level permissions, to include and execute arbitrary…
*-5.4.2
5.4.3
13/03/2023
Shopping Cart & eCommerce Store <= 5.2.6 – Cross-Site Request Forgery
The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the 'wp-easycart-submit-newsletter' function. This makes it possible for unauthenticated…
*-5.2.6
5.3.0
15/04/2022
Shopping Cart & eCommerce Store <= 5.2.4 – Cross-Site Request Forgery to Settings Update
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.4. This is due to missing or incorrect nonce validation on the 'ec_admin_ajax_save_design_settings' AJAX action. This makes…
*-5.2.4
5.2.5
28/03/2022
Shopping Cart & eCommerce Store <= 5.1.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.
*-5.1.0
5.1.5
18/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.