Junglewise Threat Intelligence

CVE-2026-57314: SureCart unauthenticated reflected XSS in WordPress plugin

CVE-2026-57314 · Severity: high · CVSS 7.1 · Published 2026-06-26

Executive brief

SureCart is a popular e-commerce platform for WordPress used to manage online stores and payments. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized actions being performed in the context of an administrator's session, such as changing site settings or redirecting customers to fraudulent pages. This occurs when a site administrator or visitor clicks on a specially crafted link provided by the attacker.

Technical details

The SureCart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions up to and including 4.3.2 due to insufficient input sanitization and output escaping. An unauthenticated remote attacker can exploit this by sending a crafted request to a vulnerable page. If a victim (typically an administrator) interacts with the malicious link or request, the attacker's script executes within the victim's browser session. This can lead to session hijacking, unauthorized administrative actions, or site defacement. The issue is resolved in version 4.3.3.

Affected products

  • SureCart SureCart <= 4.3.2

Timeline

  • 2026-05-17: disclosed: Vulnerability reported by researcher Bonds
  • 2026-06-26: advisory: Patchstack and NVD published the advisory
  • 2026-06-26: patched: Fixed in version 4.3.3

References

Related threats