WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Ecwid by Lightspeed Ecommerce Shopping Cart

Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.

12Reported vulnerabilities
9.8Highest CVSS score
7.0.9Latest version
20,000+Active installs

What to do now

Update Ecwid by Lightspeed Ecommerce Shopping Cart to 7.0.9 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 8, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-af5a58d1-946a-451b-bc8b-a397345ae89a Critical 9.8 4.4.3 and earlier 4.4.4 August 8, 2016
CVE-2026-1750 High 8.8 0.3% 0 to 7.0.7 (inclusive) 7.0.8 February 15, 2026
CVE-2025-32195 Medium 6.4 0.4% 7.0 and earlier 7.0.1 April 4, 2025
CVE-2024-2456 Medium 6.4 0.4% 6.12.10 and earlier 6.12.11 March 29, 2024
CVE-2023-24408 Medium 6.4 0.4% 6.11.4 and earlier 6.11.5 March 17, 2023
CVE-2026-14332 Medium 5.4 0.2% 0 up to (but not including) 7.0.9 7.0.9 August 13, 2026
CVE-2026-24613 Medium 5.3 0.2% 7.0.6 and earlier 7.0.7 January 12, 2026
WF-f3d5bc99-2b55-4e19-8304-e56f3d4a2f1a Medium 5.4 6.12.3 and earlier 6.12.4 November 7, 2023
WF-d8a12e1d-f46a-499e-bfd6-185d5b955071 Medium 5.4 6.10.22 and earlier 6.10.23 July 9, 2022
CVE-2026-24580 Medium 4.3 0.2% 7.0.5 and earlier 7.0.6 January 19, 2026
CVE-2023-51533 Medium 4.3 0.2% 6.12.4 and earlier 6.12.5 November 28, 2023
CVE-2023-24377 Medium 4.3 0.3% 6.11.3 and earlier 6.11.4 January 27, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.