CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104119

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite inst

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104119 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104119

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite inst

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]