๐Ÿ” CVE Alert

CVE-2026-104119

UNKNOWN 0.0

Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.

Vendor unknown
Product simple shopping cart
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple shopping cart

Be the first to know when new unknown vulnerabilities affecting unknown simple shopping cart are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple Shopping Cart
0 < 5.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/

Credits

Krugov Artyom WPScan