PT-2026-8223 · Unknown+1 · Lightspeed Ecommerce+1

Duc193

+1

·

Publicado

2026-02-15

·

Atualizado

2026-02-20

·

CVE-2026-1750

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress versions through 7.0.7
Description The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is susceptible to a privilege escalation issue. An authenticated attacker with minimal permissions, such as a subscriber, can gain store manager access to the site. This is possible due to a missing capability check within the save custom user profile fields function. Specifically, attackers can supply the ec store admin access parameter during a profile update to escalate their privileges.
Recommendations Versions prior to 7.0.7 should be updated to address this issue. As a temporary workaround, restrict user roles and closely monitor site activity for unauthorized access attempts.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1750

Produtos afetados

Ecwid By Lightspeed Ecommerce Shopping Cart
Lightspeed Ecommerce