CVE-2026-14332: Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14332?
The severity of CVE-2026-14332 is classified as medium with a score of 5.4.
How do I fix CVE-2026-14332?
To fix CVE-2026-14332, update the Ecwid by Lightspeed Ecommerce Shopping Cart plugin to version 7.0.9 or later.
What does CVE-2026-14332 affect?
CVE-2026-14332 affects the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin versions prior to 7.0.9.
Who is at risk with CVE-2026-14332?
Authenticated users with subscriber roles are at risk with CVE-2026-14332 as they can disconnect the store.
What is the impact of CVE-2026-14332?
The impact of CVE-2026-14332 is that it allows authenticated users to take the storefront offline.