Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104119— Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials

Quick assessment

Affected
Unknown Simple Shopping Cart
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Simple Shopping Cart WordPress 插件在 5.2.6 版本之前,在将某些设置字段值输出到管理员设置页面之前未对其进行转义处理,从而允许具有较高权限的用户(如管理员)执行存储型跨站脚本(Stored XSS)攻击。该漏洞在 multisite(多站点)环境中影响尤为显著,因为在这些环境中,管理员通常不具备 权限。

AI Predicted 6.1 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104119

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Simple Shopping Cart 0 ~ 5.2.6 -

II. Public POCs for CVE-2026-104119

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104119

请登录查看更多情报信息。

Other References for CVE-2026-104119 (1)

Same Patch Batch · Unknown · 2026-10-04 · 6 CVEs total

CVE-2026-93549 CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
CVE-2026-97332 User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite
CVE-2026-86817 Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure
CVE-2026-17005 Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
CVE-2026-104118 Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR

IV. Related Vulnerabilities

V. Comments for CVE-2026-104119

No comments yet


Leave a comment