GHSA-p57v-42f3-wfqrunknown

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field...

Published
October 4, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (1)

📋 Description

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.

🔗 References (3)