Vulnerabilities
CVE-2026-1750 - Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - authenticated (subscriber+...
CVE ID : CVE-2026-1750 Published : Feb. 15, 2026, 3:24 a.m. | 51 minutes ago Description : The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to supply the 'ec_store_admin_access' parameter during a profile update and gain store manager access to the site. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CVE ID
Published
Feb. 15, 2026
Affected Product:
WordPress
Impact:
Privilege Escalation