← WordPress Vulnerabilities
WordPress security by component

Wp Easycart

Wp Easycart adds ecommerce functionality for managing products, shopping carts, checkout, orders, and payments in WordPress.

Wp Easycart (wp-easycart) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 8.8.

Plugin slug: wp-easycart

CVE-2026-17553: WP EasyCart lets store managers change options and create administrator accounts

WP EasyCart through 5.9.3 passes every POST key received by ec_ajax_save_page_default_options() directly to update_option() without an allowlist. Its authorization check accepts either manage_options or wpec_manager; the built-in wpec_store_manager role holds the latter, and eligible users receive the required nonce in frontend product or category templates. A Store Manager can enable registration and set the default role to administrator, then register a new administrator account.

PublishedSep 09, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-easycart
Safe version
Sep 09, 2026 CVE-2026-17553
WP EasyCart lets store managers change options and create administrator accounts
WP EasyCart through 5.9.3 passes every POST key received by ec_ajax_save_page_default_options() directly to update_option() without an allowlist. Its authorization check accepts either manage_options or wpec_manager; the built-in wpec_store_manager role holds the latter, and eligible users receive the required nonce in frontend product or category templates. A Store Manager can enable registration and set the default role to administrator, then register a new administrator account.
See mitigation notes
CVE7.2
NVDPending
Sep 01, 2026 CVE-2026-17589
Wp Easycart permits second-order Administrator-level SQL injection
Wp Easycart through 5.9.2 accepts an unsanitized product_order value through ec_ajax_save_page_options and stores it in ec_pageoption. The plugin later retrieves the value with stripslashes() and concatenates it into SQL on store-page requests, allowing an Administrator to persist a second-order SQL injection payload and extract sensitive database information.
See mitigation notes
CVE4.9
NVDPending
Jul 02, 2026 CVE-2026-57765
WP EasyCart: SQL injection
WP EasyCart is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 5.9.0.
See mitigation notes
CVE8.5
NVDPending
Mar 13, 2026 CVE-2026-32422
WP EasyCart: SQL injection
WP EasyCart is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Dec 09, 2025 CVE-2025-62997
WP EasyCart: A security weakness
WP EasyCart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 20, 2024 CVE-2024-7827
Shopping Cart & eCommerce Store: SQL injection
Shopping Cart & eCommerce Store is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Jun 11, 2024 CVE-2024-35667
WP EasyCart: A security weakness
WP EasyCart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2024 CVE-2024-32452
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jul 12, 2023 CVE-2023-3023
WP EasyCart: SQL injection
WP EasyCart is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Jun 09, 2023 CVE-2023-2896
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-2895
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-2894
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-2893
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-2892
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD4.3
Jun 09, 2023 CVE-2023-2891
WP EasyCart: Cross-site request forgery
WP EasyCart is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD4.3
Apr 03, 2023 CVE-2023-1124
Shopping Cart & eCommerce Store: A security weakness
Shopping Cart & eCommerce Store is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Aug 19, 2021 CVE-2021-34645
Shopping Cart & eCommerce Store: Cross-site request forgery
Shopping Cart & eCommerce Store is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Oct 06, 2017 CVE-2015-2673
Wp Easycart: A security weakness
Wp Easycart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8
Jan 15, 2015 CVE-2014-9308
Wp Easycart: A security weakness
Wp Easycart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD6.5
Jul 11, 2014 CVE-2014-4942
Wp Easycart: A security weakness
Wp Easycart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.0