Surecart
Surecart: vulnerabilidades y CVE
Surecart tiene 11 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses9
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97245 | Alta (7.2) | 0.34% | — | 30 sept 2026 | Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. |
| CVE-2026-75793 | Media (6.5) | 0.27% | — | 6 sept 2026 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session… |
| CVE-2026-18480 | Alta (8.8) | 0.24% | — | 6 sept 2026 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change… |
| CVE-2026-32548 | Media (5.3) | 0.31% | — | 6 ago 2026 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. |
| CVE-2026-7655 | Alta (8.1) | 0.47% | — | 11 jul 2026 | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating… |
| CVE-2026-57314 | Alta (7.1) | 0.25% | — | 26 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. |
| CVE-2026-57313 | Media (6.5) | 0.22% | — | 26 jun 2026 | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. |
| CVE-2026-9065 | Crítica (9.3) | 0.43% | — | 20 may 2026 | SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'.… |
| CVE-2026-39488 | Media (6.5) | 0.25% | — | 8 abr 2026 | Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2. |
| CVE-2024-43970 | Media (6.1) | 0.27% | — | 18 sept 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3. |
| CVE-2023-41241 | Media (4.8) | 0.36% | — | 27 sept 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.