Sceawere

Vulnerability Detail

CVE-2026-14332UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ecwid Ecommerce Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
Unknown
Product
Ecwid by Lightspeed Ecommerce Shopping Cart
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-13T09:17:12.017Z",
  "pubdate": "2026-08-13T09:17:12.017Z",
  "executiveSummary": "An authorization bypass vulnerability exists in the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before version 7.0.9, characterized by a missing capability check and nonce verification on a critical store-management action.\nThe vulnerability allows any authenticated user with minimal privileges, such as a subscriber, to initiate a store-disconnection action that takes the active storefront completely offline.\nThe primary impact is a severe denial of service (DoS) affecting the e-commerce availability of the targeted WordPress instance, requiring manual administrative intervention to reconnect the store and restore functionality.\nThe attack vector requires low-privileged network access where an attacker must possess authenticated session credentials on the target WordPress site.\nThe root cause stems from improper access control enforcement within the administrative routing or action-handling logic of the affected plugin, failing to validate whether the requesting user possesses sufficient administrative privileges before executing sensitive store-management routines.\nOrganizations utilizing the affected software face operational disruption risks, necessitating immediate remediation to prevent unauthorized service termination by low-privileged internal or compromised accounts.",
  "technicalDetails": "The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin prior to version 7.0.9 suffers from an inadequate access control implementation concerning specific store-management functionalities.\nSpecifically, the vulnerable component fails to execute essential security checks, omitting both capability verification (such as checking for 'manage_options' or equivalent administrative capabilities) and cryptographic nonce validation (number used once) on a state-changing endpoint or action handler.\nAuthentication requirements are minimal; any valid user account provisioned with subscriber-level privileges can successfully interact with the vulnerable action handler.\nNetwork exposure is inherent to the WordPress application layer, accessible over standard HTTP/HTTPS protocols where the target application processes incoming requests from authenticated sessions.\nThe attack flow proceeds as follows: 1) An attacker authenticates to the WordPress site with low-level privileges (e.g., subscriber role). 2) The attacker crafts or intercepts an HTTP request directed at the unprotected store-management action responsible for disconnecting the e-commerce integration. 3) Because the server-side code lacks proper capability checks and cryptographic nonces, it processes the request directly without validating the user's authorization level. 4) The plugin executes the disconnection routine, severing the connection between the WordPress site and the Ecwid e-commerce platform.\nThe post-exploitation impact results in an immediate denial of service (DoS) for the storefront, rendering products unpurchasable and removing the shopping cart interface from public visibility until an administrator manually re-establishes the integration via the WordPress dashboard.\nThe affected product is the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin across all versions prior to 7.0.9."
}
CVE-2026-14332: Ecwid Ecommerce Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere