Software intelligence
Important: Wp Easycart appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
23
Latest advisory
2 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
wp-easycart
Plugin
This catalog lists 23 known advisories affecting Wp Easycart. The most recent was published on 2 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Shopping Cart & eCommerce Store <= 5.9.1 - Authenticated (Contributor+) SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 2 July 2026
EasyCart <= 5.8.13 - Authenticated (Contributor+) SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 27 February 2026
EasyCart <= 5.8.11 - Unauthenticated Information Exposure
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 8 December 2025
Known Wp Easycart advisories published by month.
CVE-2023-2891 · Published 27 May 2023
Affected versions: ≤ 5.4.8
CVE-2023-1124 · Published 13 March 2023
Affected versions: ≤ 5.4.2
No CVE assigned · Published 15 April 2022
Affected versions: ≤ 5.2.6
No CVE assigned · Published 28 March 2022
Affected versions: ≤ 5.2.4
CVE-2021-34645 · Published 18 August 2021
Affected versions: ≤ 5.1.0
CVE-2015-2673 · Published 26 February 2015
Affected versions: ≥ 1.1.30 and ≤ 3.0.20
CVE-2014-9308 · Published 9 January 2015
Affected versions: < 3.0.16
CVE-2014-4942 · Published 28 May 2014
Affected versions: ≤ 2.0.5
SiteRespond Defence matches your installed Wp Easycart version against this catalog when the Defence plugin is connected to your WordPress site.