WordPress security by component
Simple Shopping Cart
Plugin description
Simple Shopping Cart is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 8.2.
Plugin slug:
wordpress-simple-paypal-shopping-cartLatest vulnerability
CVE-2026-48868: Simple Shopping Cart: A security weakness
Simple Shopping Cart is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.2.9.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2026-48868
Simple Shopping Cart: A security weakness
Simple Shopping Cart is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.2.9.
|
5.3.0 |
CVE7.5
NVDPending
|
| May 01, 2025 |
CVE-2025-3890
WordPress Simple Shopping Cart: Cross-site scripting
WordPress Simple Shopping Cart is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 01, 2025 |
CVE-2025-3889
WordPress Simple Shopping Cart: A security weakness
WordPress Simple Shopping Cart is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| May 01, 2025 |
CVE-2025-3874
WordPress Simple Shopping Cart: A security weakness
WordPress Simple Shopping Cart is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Apr 23, 2025 |
CVE-2025-3530
WordPress Simple Shopping Cart: A security weakness
WordPress Simple Shopping Cart is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 23, 2025 |
CVE-2025-3529
WordPress Simple Shopping Cart: Sensitive information exposure
WordPress Simple Shopping Cart is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE8.2
NVDPending
|
| Dec 24, 2024 |
CVE-2024-12622
WordPress Simple Shopping Cart: Cross-site scripting
WordPress Simple Shopping Cart is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 27, 2024 |
CVE-2023-6497
WordPress Simple Shopping Cart: Cross-site scripting
WordPress Simple Shopping Cart is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.8
|
| Mar 16, 2023 |
CVE-2023-1431
WP Simple Shopping Cart: Sensitive information exposure
WP Simple Shopping Cart is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jan 23, 2023 |
CVE-2022-4672
WordPress Simple Shopping Cart: Cross-site scripting
WordPress Simple Shopping Cart is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| May 13, 2014 |
CVE-2013-2705
Wordpress Simple Paypal Shopping Cart: Cross-site request forgery
Wordpress Simple Paypal Shopping Cart is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.8
NVD6.8
|