{"id":"CVE-2026-104119","title":"The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site …","summary":"The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site …","severity":"none","cwe":["CWE-79"],"product":"Simple Shopping Cart","affected":["simple_shopping_cart < 5.2.6"],"published":"2026-10-04","updated":"2026-10-04","sourceUpdated":"2026-10-04T07:16:32.963","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104119","references":[{"url":"https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-04T06:55:02.310Z","slug":"CVE-2026-104119","body":"## Overview\n\nThe Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}