The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
CVE-2026-104119
NONE
Updated Oct 04, 2026
Unknown
unknown:simple shopping cart
CVE Details
CVE ID
CVE-2026-104119
Published Date
Oct 04, 2026
Vendor
Unknown
Severity
NONE
Impact
Minimal impact
Source
View Advisory