PLUGIN SECURITY

Is Surecart safe?

Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!

What this plugin does

  • Slug: surecart
  • Author: SureCart
  • 80000+ active installs
  • 96/100 rating (278 reviews on wordpress.org)
  • 3654169 all-time downloads
  • On WordPress.org since 2022-07-20

ecommerceonline storepaymentsstripesubscriptions

Maintenance status

  • Latest known version: 4.6.3
  • Last updated: 2026-08-25 5:26pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+

Known vulnerabilities

8 known CVEs on file for Surecart. Reported between 2023 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32548 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.6.3 Missing Authorization Medium 5.3 < 4.6.3 4.6.3 2026-08-06 ✓ fixed in latest
CVE-2026-57314 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 4.3.3 4.3.3 2026-06-26 ✓ fixed in latest
CVE-2026-7655 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.0 Weak Password Recovery Mechanism for Forgotten Password High 8.1 < 4.3.0 4.3.0 2026-06-26 ✓ fixed in latest
CVE-2026-57313 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.2.3 4.2.3 2026-06-25 ✓ fixed in latest
CVE-2026-9065 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 4.2.1 4.2.1 2026-05-20 ✓ fixed in latest
CVE-2026-39488 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.0.3 Medium 6.5 < 4.0.3 4.0.3 2026-03-26 ✓ fixed in latest
CVE-2024-43970 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 2.29.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.29.4 2.29.4 2024-08-28 ✓ fixed in latest
CVE-2023-41241 SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 2.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.5.1 2.5.1 2023-08-29 ✓ fixed in latest

How to fix it

Keep Surecart updated — 4.6.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.