CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104119
UNKNOWNCVSS 0NVD feed
Published 4 October 2026 · tracked since 4 October 2026
Description
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite inst
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-86817
- CVE-2026-93549
- CVE-2026-97332
- CVE-2026-17005
- CVE-2026-104118
- CVE-2026-105123 HIGH 8.8
- CVE-2026-105124 MEDIUM 6.1
- CVE-2026-105125 LOW 3.7
- CVE-2026-105118 MEDIUM 4.7
- CVE-2026-97873