---
id: CVE-2026-104119
title: >-
  The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of
  its settings field values before outputting them on an admin settings page,
  allowing high-privilege users such as administrators to perform Stored
  Cross-Site …
summary: >-
  The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of
  its settings field values before outputting them on an admin settings page,
  allowing high-privilege users such as administrators to perform Stored
  Cross-Site …
severity: none
cwe:
  - CWE-79
product: Simple Shopping Cart
affected:
  - simple_shopping_cart < 5.2.6
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T07:16:32.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104119'
references:
  - url: 'https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T06:55:02.310Z'
---

## Overview

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
