CVE-2026-94124: WordPress WP EasyCart plugin <= 5.9.4 - SQL Injection vulnerability
Published Sep 23, 2026
·Updated
Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
Affected Software
1 affected component
WP EasyCart WP EasyCart<=5.9.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP EasyCart pluginto a version that resolves this vulnerability.Fixed in 6.0.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs Contributor-level privileges. No user interaction is required, and the attack can be performed remotely.
2
What is the likely impact if the vulnerability is exploited?
Successful exploitation may allow disclosure of sensitive information through SQL injection. The supplied vector also indicates a low availability impact and that the impact can extend beyond the vulnerable component.
3
Which versions are known to be affected?
WP EasyCart versions up to and including 5.9.4 are affected.