๐Ÿ” CVE Alert

CVE-2024-14015

HIGH 7.1

Studiocart <= 2.9.0 - Reflected XSS

CVSS Score
7.1
EPSS Score
1.2%
EPSS Percentile
79th

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Vendor unknown
Product wordpress ecommerce plugin
Published Nov 24, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wordpress ecommerce plugin

Be the first to know when new high vulnerabilities affecting unknown wordpress ecommerce plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WordPress eCommerce Plugin
0 โ‰ค 2.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1a70927a-e345-4e2f-98da-1235f4482cc0/

Credits

Hassan Khan Yusufzai - Splint3r7 WPScan