Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access
Ecwid by Lightspeed Ecommerce Shopping Cart
Minimum safe version
7.0.8
Update to 7.0.8 or later to address 20 fixable vulnerabilities
CVE-2026-24613
CVE-2026-24580
CVE-2025-32195
CVE-2024-13795
Ecwid Ecommerce Shopping Cart < 6.12.4 - Missing Authorization on multiple functions
CVE-2024-2456
CVE-2023-6292
WordPress Ecwid Shopping Cart Plugin <= 6.12.4 is vulnerable to Cross Site Request Forgery (CSRF)
Ecwid Ecommerce Shopping Cart <= 6.12.4 - Cross-Site Request Forgery
WordPress Ecwid Shopping Cart Plugin <= 6.12.3 is vulnerable to Broken Access Control
Ecwid Ecommerce Shopping Cart <= 6.12.3 - Missing Authorization on multiple functions
Ecwid Shopping Cart < 6.10.23 - Insufficient Access Control
CVE-2023-24408
CVE-2023-24377
Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object injection
Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object Injection
Ecwid Ecommerce Shopping Cart <= 6.10.22 - Insufficient Access Control on Multiple AJAX Actions
CVE-2022-2432
WordPress Ecwid Shopping Cart Plugin <= 4.4.3 - Unauthenticated PHP Object Injection