Known Vulnerabilities for Surecart by Surecart
Listed below are 1 of the newest known vulnerabilities associated with "Surecart" by "Surecart".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75793 json | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress a... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-57314 json | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-57313 json | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-32548 json | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-18480 json | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same accoun... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-13039 json | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to auth... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-7655 json | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including... | Not Provided | 2026-07-11 | 2026-07-15 |
| CVE-2023-41241 json | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Store... | 4.8 - MEDIUM | 2023-09-27 | 2023-09-28 |