PLUGIN SECURITY
Is Surecart safe?
Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!
What this plugin does
- Slug:
surecart - Author: SureCart
- 80000+ active installs
- 96/100 rating (278 reviews on wordpress.org)
- 3654169 all-time downloads
- On WordPress.org since 2022-07-20
ecommerceonline storepaymentsstripesubscriptions
Maintenance status
- Latest known version: 4.6.3
- Last updated: 2026-08-25 5:26pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
Known vulnerabilities
8 known CVEs on file for Surecart. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-32548 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.6.3 | Missing Authorization | Medium 5.3 | < 4.6.3 | 4.6.3 | 2026-08-06 | ✓ fixed in latest |
| CVE-2026-57314 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 4.3.3 | 4.3.3 | 2026-06-26 | ✓ fixed in latest |
| CVE-2026-7655 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.0 | Weak Password Recovery Mechanism for Forgotten Password | High 8.1 | < 4.3.0 | 4.3.0 | 2026-06-26 | ✓ fixed in latest |
| CVE-2026-57313 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 4.2.3 | 4.2.3 | 2026-06-25 | ✓ fixed in latest |
| CVE-2026-9065 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 4.2.1 | 4.2.1 | 2026-05-20 | ✓ fixed in latest |
| CVE-2026-39488 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.0.3 | — | Medium 6.5 | < 4.0.3 | 4.0.3 | 2026-03-26 | ✓ fixed in latest |
| CVE-2024-43970 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 2.29.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.29.4 | 2.29.4 | 2024-08-28 | ✓ fixed in latest |
| CVE-2023-41241 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 2.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.5.1 | 2.5.1 | 2023-08-29 | ✓ fixed in latest |
How to fix it
Keep Surecart updated — 4.6.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce — 7000000+ active installs — 90/100 (4820)
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation — 1000000+ active installs — 86/100 (815) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
- WPML Multilingual & Multicurrency for WooCommerce — 100000+ active installs — 84/100 (453)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.