Executive brief
The Easy Cart plugin for WordPress, which provides e-commerce functionality, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.
Technical details
The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping in the ectp_add_to_cart() function. While the function uses sanitize_text_field() on shortcode attributes such as 'itemid', 'product_name', and 'price', this WordPress function does not escape double quotes. Consequently, an attacker can use double quotes to break out of the HTML attribute context and inject malicious event handlers (e.g., onmouseover). This vulnerability requires Contributor-level authentication or higher to exploit via the 'add_to_cart' shortcode. The injected scripts are stored and executed in the browser of any user who views the compromised page.
Affected products
- Easy Cart Easy Cart up to and including 1.8
Timeline
- 2026-06-02: disclosed: Vulnerability published to the CVE list.
- 2026-06-02: advisory: Wordfence published a vulnerability report.
References
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php
- https://plugins.trac.wordpress.org/browser/easy-cart/tags/1.8/plugin.php