CVE-2026-104119: Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfilteredhtml capability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Simple Shopping Cart WordPress pluginto a version that resolves this vulnerability.Fixed in 5.2.6
Event History
Frequently Asked Questions
Which environments are most affected by this issue?
WordPress multisite installations are notably affected because administrators may lack the unfiltered_html capability. The issue requires access by a high-privilege user such as an administrator.
What must an attacker be able to do to exploit it?
They need high-privilege access sufficient to set affected plugin settings values, such as the PayPal API credential fields. The malicious value is then stored and rendered on an administrator settings page without proper escaping.
How can I determine whether my site is affected?
Check whether Simple Shopping Cart is installed at a version earlier than 5.2.6. Review the plugin's stored settings, particularly PayPal API credential-related fields, for unexpected HTML or script content.