PatchSiren cyber security CVE debrief
CVE-2026-104119 Simple Shopping Cart CVE debrief
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
- Vendor
- Simple Shopping Cart
- Product
- Simple Shopping Cart WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
WordPress administrators and security teams, especially those managing multisite installations, should assess exposure and prioritize remediation for the Simple Shopping Cart plugin vulnerability.
Why it matters
CVE-2026-104119 is a Stored Cross-Site Scripting vulnerability in the Simple Shopping Cart WordPress plugin. High-privilege users, such as administrators, may exploit this vulnerability in multisite installations where administrators lack the unfiltered_html capability. Defenders should assess exposure, prioritize remediation, and verify plugin versions to prevent potential attacks.
- Potential for Stored Cross-Site Scripting attacks on admin settings pages
- Notably impactful on multisite installations where administrators do not have the unfiltered_html capability
- Requires verification of affected versions and potential impact
- Remediation priority for WordPress installations using the Simple Shopping Cart plugin
Technical summary
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks. This vulnerability is notably impactful on multisite installations where administrators do not have the unfiltered_html capability. The vulnerability allows attackers to inject malicious scripts, potentially leading to unauthorized actions and data breaches. Defenders should assess exposure, prioritize remediation, and verify plugin versions to prevent potential attacks.
Defensive priority
Assess exposure and prioritize remediation for WordPress installations using the Simple Shopping Cart plugin, especially in multisite environments.
Recommended defensive actions
- Assess exposure by checking WordPress installations for the Simple Shopping Cart plugin version before 5.2.6
- Prioritize remediation for multisite installations where administrators lack the unfiltered_html capability
- Verify plugin version and update to 5.2.6 or later if vulnerable
- Monitor for potential Stored Cross-Site Scripting attacks on admin settings pages
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the full scope of affected versions and potential impact. The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page. The vulnerability allows high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104119 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104119
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104119 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104119
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.