PatchSiren

Ecwid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ecwid CVE published 2026-08-13

CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 is vulnerable to unauthorized store disconnection due to missing capability checks and nonce verification in store-management actions. This allows any authenticated user, including subscribers, to take the storefront offline until an administrator reconnects it. The vulnerability has a CVSS score of 5.4 and a severity rating of [truncated]