MEDIUM
Ecwid
CVE published 2026-08-13
CVE-2026-14332
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 is vulnerable to unauthorized store disconnection due to missing capability checks and nonce verification in store-management actions. This allows any authenticated user, including subscribers, to take the storefront offline until an administrator reconnects it. The vulnerability has a CVSS score of 5.4 and a severity rating of [truncated]