PT-2026-8223 · Unknown+1 · Lightspeed Ecommerce+1

Duc193

+1

·

Published

2026-02-15

·

Updated

2026-02-20

·

CVE-2026-1750

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress versions through 7.0.7
Description The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is susceptible to a privilege escalation issue. An authenticated attacker with minimal permissions, such as a subscriber, can gain store manager access to the site. This is possible due to a missing capability check within the save custom user profile fields function. Specifically, attackers can supply the ec store admin access parameter during a profile update to escalate their privileges.
Recommendations Versions prior to 7.0.7 should be updated to address this issue. As a temporary workaround, restrict user roles and closely monitor site activity for unauthorized access attempts.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-1750

Affected Products

Ecwid By Lightspeed Ecommerce Shopping Cart
Lightspeed Ecommerce