WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Ecwid Shopping Cart?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Ecwid Shopping Cart — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: ecwid-shopping-cart
  • 20000+ instalaciones activas

e-commerceecommerceonline storeshopping cartstorefront

Estado de mantenimiento

  • Última versión conocida: 7.0.8
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

11 CVEs conocidos registrados para Ecwid Shopping Cart.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-24580 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.6 Falta de control de autorización Media 4,3 < 7.0.6 7.0.6 2026-01-19 ✓ corregido en la última versión
CVE-2026-24613 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.7 Falta de control de autorización Media 5,3 < 7.0.7 7.0.7 2026-01-12 ✓ corregido en la última versión
CVE-2025-32195 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 7.0.1 7.0.1 2025-04-04 ✓ corregido en la última versión
CVE-2024-13795 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 6.12.28 6.12.28 2025-02-17 ✓ corregido en la última versión
CVE-2024-2456 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11 Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) Media 6,4 < 6.12.11 6.12.11 2024-03-29 ✓ corregido en la última versión
CVE-2023-51533 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 6.12.5 6.12.5 2024-02-28 ✓ corregido en la última versión
CVE-2023-6292 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 6.12.5 6.12.5 2024-01-16 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 Desconocido < 6.12.5 6.12.5 2023-11-28 ✓ corregido en la última versión

CVE-2026-24580

The Ecwid Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.0.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-24613

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-32195

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13795

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send deactivation messages on behalf of a site owner via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2456

Update the WordPress Ecwid Shopping Cart plugin to the latest available version (at least 6.12.11). Krzysztof Zając discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ecwid Shopping Cart Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.12.11. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-51533

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticated attackers to modify several of the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-6292 may be a duplicate of this issue.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2023-6292

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticated attackers to modify several of the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-6292 may be a duplicate of this issue.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 15 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 Desconocido < 6.12.4 6.12.4 2023-11-09 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 Desconocido < 6.12.4 6.12.4 2023-11-07 ✓ corregido en la última versión
CVE-2023-24408 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 6.11.5 6.11.5 2023-03-17 ✓ corregido en la última versión
CVE-2023-24377 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.4 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 6.11.4 6.11.4 2023-01-27 ✓ corregido en la última versión
CVE-2022-2432 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 6.10.24 6.10.24 2022-07-11 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23 Desconocido < 6.10.23 6.10.23 2022-07-09 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 Desconocido < 4.4.4 4.4.4 2016-08-08 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 Desconocido < 4.4.4 4.4.4 2016-08-08 ✓ corregido en la última versión
CVE-2026-1750 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.8 Gestión incorrecta de privilegios Alta 8,8 < 7.0.8 7.0.8 0000-00-00 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 Desconocido < 4.4.4 4.4.4 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23 Desconocido < 6.10.23 6.10.23 ✓ corregido en la última versión
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 Desconocido < 6.12.4 6.12.4 ✓ corregido en la última versión
Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object Injection Desconocido < 4.4.4 4.4.4 ✓ corregido en la última versión
Ecwid Shopping Cart < 6.10.23 - Insufficient Access Control Desconocido < 6.10.23 6.10.23 ✓ corregido en la última versión
Ecwid Ecommerce Shopping Cart < 6.12.4 - Missing Authorization on multiple functions Desconocido < 6.12.4 6.12.4 ✓ corregido en la última versión

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

Update the WordPress Ecwid Shopping Cart plugin to the latest available version (at least 6.12.4). Unknown discovered and reported this Broken Access Control vulnerability in WordPress Ecwid Shopping Cart Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 6.12.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-24408

The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-24377

Update the WordPress Ecwid Shopping Cart plugin to the latest available version (at least 6.11.4). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Ecwid Shopping Cart Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 6.11.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-2432

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Insufficient Access Control on Multiple AJAX Actions in versions up to, and including, 6.10.22. This allows any authenticated user to perform multiple AJAX actions including creating product and category pages as well as changing, publishing, and unpublishing the storefront page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

Because of this vulnerability, attackers can execute arbitrary PHP code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 via deserialization of untrusted input from the vulnerable cookie parameter 'ecwid_oauth_state' in the _load_state function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1750

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to supply the 'ec_store_admin_access' parameter during a profile update and gain store manager access to the site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: euvd.enisa.europa.eu

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4

The Ecwid Ecommerce Shopping Cart WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23

The plugin does not have adequate authorisation in various AJAX actions, which could allow users with a role as low as Subscriber to call them and perform unauthorised actions, such as creating product and category pages, and editing the storefront page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4

The plugin is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple functions in all versions up to, and including, 6.12.3. This makes it possible for authenticated attackers to access developer tool pages.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Ecwid Shopping Cart actualizado — 7.0.8 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.