PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104119 Simple Shopping Cart CVE debrief

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.

Vendor
Simple Shopping Cart
Product
Simple Shopping Cart WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

WordPress administrators and security teams, especially those managing multisite installations, should assess exposure and prioritize remediation for the Simple Shopping Cart plugin vulnerability.

Why it matters

CVE-2026-104119 is a Stored Cross-Site Scripting vulnerability in the Simple Shopping Cart WordPress plugin. High-privilege users, such as administrators, may exploit this vulnerability in multisite installations where administrators lack the unfiltered_html capability. Defenders should assess exposure, prioritize remediation, and verify plugin versions to prevent potential attacks.

  • Potential for Stored Cross-Site Scripting attacks on admin settings pages
  • Notably impactful on multisite installations where administrators do not have the unfiltered_html capability
  • Requires verification of affected versions and potential impact
  • Remediation priority for WordPress installations using the Simple Shopping Cart plugin

Technical summary

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks. This vulnerability is notably impactful on multisite installations where administrators do not have the unfiltered_html capability. The vulnerability allows attackers to inject malicious scripts, potentially leading to unauthorized actions and data breaches. Defenders should assess exposure, prioritize remediation, and verify plugin versions to prevent potential attacks.

Defensive priority

Assess exposure and prioritize remediation for WordPress installations using the Simple Shopping Cart plugin, especially in multisite environments.

Recommended defensive actions

  • Assess exposure by checking WordPress installations for the Simple Shopping Cart plugin version before 5.2.6
  • Prioritize remediation for multisite installations where administrators lack the unfiltered_html capability
  • Verify plugin version and update to 5.2.6 or later if vulnerable
  • Monitor for potential Stored Cross-Site Scripting attacks on admin settings pages
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the full scope of affected versions and potential impact. The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page. The vulnerability allows high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104119 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104119

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104119 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104119

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.