Simple Shopping Cart WordPress 插件在 5.2.6 版本之前,在将某些设置字段值输出到管理员设置页面之前未对其进行转义处理,从而允许具有较高权限的用户(如管理员)执行存储型跨站脚本(Stored XSS)攻击。该漏洞在 multisite(多站点)环境中影响尤为显著,因为在这些环境中,管理员通常不具备 权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Simple Shopping Cart | 0 ~ 5.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93549 | CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-97332 | User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite | |
| CVE-2026-86817 | Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure | |
| CVE-2026-17005 | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| CVE-2026-104118 | Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR |
No comments yet