🚨 CVE-2026-17553

CVENOTIFYneutralcyber2026-09-09 04:33:40 UTC
AdYour ad here[email protected]

🚨 CVE-2026-17553 The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's built-in 'wpec_store_manager' role holds 'wpec_manager' but not 'manage_options', and…

Read the full story at cvenotify ↗
AdYour ad here[email protected]