Junglewise Threat Intelligence

CVE-2026-8880: RomanCart Ecommerce Stored XSS in romancart_button shortcode

CVE-2026-8880 · Severity: medium · CVSS 6.4 · Published 2026-06-09

Executive brief

The RomanCart Ecommerce plugin for WordPress, which allows site owners to integrate shopping cart functionality, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site visitors or the theft of sensitive session information.

Technical details

The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the romancart_button_shortcode() function. Specifically, the 'blclass' and other attributes of the [romancart_button] shortcode do not properly neutralize user-supplied data. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious JavaScript into a post or page. When other users, including administrators, view the compromised page, the script executes in their browser context. This vulnerability is present in versions up to and including 2.0.8.

Affected products

  • RomanCart RomanCart Ecommerce up to, and including, 2.0.8

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References