The SureCart plugin, a popular e-commerce plugin for WordPress, has an unauthenticated broken access control vulnerability in versions <= 4.6.2. This vulnerability, with a CVSS score of 5.3 and a severity of MEDIUM, allows attackers to bypass access controls, potentially leading to unauthorized actions. The CVE record was published on 2026-08-06T15:16:54.497Z and has not been modified since then. Users of [truncated]
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, includin [truncated]
CVE-2026-57314 is a HIGH-severity vulnerability in the SureCart plugin, affecting versions up to 4.3.2. This Unauthenticated Cross Site Scripting (XSS) vulnerability has a CVSS score of 7.1 and was published on June 26, 2026. The vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. The CVE record was last modified on June 29, 2026. Users of affected SureCart ver [truncated]
A Missing Authorization vulnerability was found in the SureCart plugin. This issue allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability affects SureCart plugin versions from n/a through 4.0.2. The CVSS score for this vulnerability is 6.5, indicating a medium severity. Users of the SureCart plugin should apply patc [truncated]