PatchSiren cyber security CVE debrief
CVE-2026-14332 Ecwid CVE debrief
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 is vulnerable to unauthorized store disconnection due to missing capability checks and nonce verification in store-management actions. This allows any authenticated user, including subscribers, to take the storefront offline until an administrator reconnects it. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Affected product deployments should be verified, and patches applied promptly. Official CVE and NVD records provide limited detail; further analysis is required. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Vendor
- Ecwid
- Product
- Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin, as well as security teams monitoring WordPress vulnerabilities, should be aware of this vulnerability. They should verify and apply patches promptly, restrict store-management actions to authorized personnel, and monitor plugin updates and security advisories. Additionally, defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
Technical summary
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 is vulnerable to unauthorized store disconnection due to missing capability checks and nonce verification in store-management actions. This allows any authenticated user, including subscribers, to take the storefront offline until an administrator reconnects it. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.
Defensive priority
Medium-priority vulnerability in a widely-used WordPress plugin; verify and apply patches promptly.
Recommended defensive actions
- Verify and apply the latest patches for the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin.
- Restrict store-management actions to authorized personnel.
- Monitor plugin updates and security advisories.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions. Official CVE and NVD records provide limited detail; further analysis required. The vulnerability allows any authenticated user, including subscribers, to disconnect the store and take the storefront offline until an administrator reconnects it. Evidence is limited; defenders should verify affected deployments, review official advisories, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14332 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14332
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14332 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14332
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/75182c5d-c7f5-4da9-bffd-1f7bf54cfd04/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.