Junglewise Threat Intelligence

CVE-2026-48868: WordPress Simple Shopping Cart IDOR in plugin

CVE-2026-48868 · Severity: high · CVSS 7.5 · Published 2026-06-15

Vendors: Tips and Tricks HQ.

Executive brief

The Simple Shopping Cart plugin for WordPress is used to manage e-commerce transactions and customer orders. A security flaw allows unauthorized individuals to access sensitive information by manipulating identifiers in web requests. This could lead to the exposure of private customer data or order details, potentially damaging the business's reputation and violating privacy regulations.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Simple Shopping Cart plugin for WordPress (versions up to and including 5.2.9). The flaw, classified as CWE-639, occurs because the application fails to perform adequate authorization checks when a user-controlled input is used to access internal database objects or files. An unauthenticated remote attacker can exploit this by modifying parameters in a request to view or interact with data they are not authorized to see, such as sensitive customer or transaction records. The vulnerability is resolved in version 5.3.0.

Affected products

  • Tips and Tricks HQ Simple Shopping Cart <= 5.2.9

Timeline

  • 2026-05-15: other: Reported by Austin Ginder
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References