PLUGIN SECURITY
Is Ecwid Shopping Cart safe?
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
What this plugin does
- Slug:
ecwid-shopping-cart - Author: Ecwid by Lightspeed Ecommerce Shopping Cart
- 20000+ active installs
- 90/100 rating (228 reviews on wordpress.org)
- 3012812 all-time downloads
- On WordPress.org since 2009-10-21
e-commerceecommerceonline storeshopping cartstorefront
Maintenance status
- Latest known version: 7.0.9
- Last updated: 2026-08-08 11:23am GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
12 known CVEs on file for Ecwid Shopping Cart.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-14332 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.9 | Missing Authorization | Medium 5.4 | < 7.0.9 | 7.0.9 | 2026-02-14 | ✓ fixed in latest |
| CVE-2026-24580 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.6 | Missing Authorization | Medium 4.3 | < 7.0.6 | 7.0.6 | 2026-01-19 | ✓ fixed in latest |
| CVE-2026-24613 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.7 | Missing Authorization | Medium 5.3 | < 7.0.7 | 7.0.7 | 2026-01-12 | ✓ fixed in latest |
| CVE-2025-32195 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 7.0.1 | 7.0.1 | 2025-04-04 | ✓ fixed in latest |
| CVE-2024-13795 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 6.12.28 | 6.12.28 | 2025-02-17 | ✓ fixed in latest |
| CVE-2024-2456 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.11 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.4 | < 6.12.11 | 6.12.11 | 2024-03-29 | ✓ fixed in latest |
| CVE-2023-6292 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 6.12.5 | 6.12.5 | 2024-01-16 | ✓ fixed in latest |
| CVE-2023-51533 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 6.12.5 | 6.12.5 | 2023-11-28 | ✓ fixed in latest |
+ 17 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 | — | Unknown | < 6.12.4 | 6.12.4 | 2023-11-09 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 | — | Unknown | < 6.12.4 | 6.12.4 | 2023-11-07 | ✓ fixed in latest |
| CVE-2023-24408 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.11.5 | 6.11.5 | 2023-03-17 | ✓ fixed in latest |
| CVE-2023-24377 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.11.4 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 6.11.4 | 6.11.4 | 2023-01-27 | ✓ fixed in latest |
| CVE-2022-2432 | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 6.10.24 | 6.10.24 | 2022-07-11 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23 | — | Unknown | < 6.10.23 | 6.10.23 | 2022-07-09 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 | — | Unknown | < 4.4.4 | 4.4.4 | 2016-08-08 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 | — | Unknown | < 4.4.4 | 4.4.4 | 2016-08-08 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.8 | Improper Privilege Management | High 8.8 | < 7.0.8 | 7.0.8 | 0000-00-00 | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 4.4.4 | — | Unknown | < 4.4.4 | 4.4.4 | — | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.23 | — | Unknown | < 6.10.23 | 6.10.23 | — | ✓ fixed in latest |
| — | Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.4 | — | Unknown | < 6.12.4 | 6.12.4 | — | ✓ fixed in latest |
| — | Ecwid Ecommerce Shopping Cart <= 4.4.3 - Unauthenticated PHP Object Injection | — | Unknown | < 4.4.4 | 4.4.4 | — | ✓ fixed in latest |
| — | Ecwid Shopping Cart < 6.10.23 - Insufficient Access Control | — | Unknown | < 6.10.23 | 6.10.23 | — | ✓ fixed in latest |
| CVE-2023-51533 | Ecwid Ecommerce Shopping Cart < 6.12.5 - Cross-Site Request Forgery | — | Unknown | < 6.12.5 | 6.12.5 | — | ✓ fixed in latest |
| — | Ecwid Ecommerce Shopping Cart < 6.12.4 - Missing Authorization on multiple functions | — | Unknown | < 6.12.4 | 6.12.4 | — | ✓ fixed in latest |
| CVE-2026-1750 | Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.8 - Subscriber+ Privilege Escalation | — | Unknown | < 7.0.8 | 7.0.8 | — | ✓ fixed in latest |
How to fix it
Keep Ecwid Shopping Cart updated — 7.0.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce — 7000000+ active installs — 90/100 (4820)
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
- WPML Multilingual & Multicurrency for WooCommerce — 100000+ active installs — 84/100 (453)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.