WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments

Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!

8Reported vulnerabilities
9.3Highest CVSS score
4.6.4Latest version
80,000+Active installs

What to do now

Update SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments to 4.6.3 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-9065 Critical 9.3 0.3% O up to (but not including) 4.2.1 4.2.1 May 20, 2026
CVE-2026-7655 High 8.1 0.5% 0 to 4.2.3 (inclusive) 4.3.0 July 11, 2026
CVE-2026-57313 Medium 6.4 0.2% 4.2.2 and earlier 4.2.3 June 25, 2026
CVE-2026-57314 Medium 6.1 0.3% 4.3.2 and earlier 4.3.3 June 26, 2026
CVE-2024-43970 Medium 6.1 0.3% 2.29.3 and earlier 2.29.4 August 28, 2024
CVE-2026-32548 Medium 5.3 0.2% 4.6.2 and earlier 4.6.3 August 6, 2026
CVE-2023-41241 Medium 4.8 0.3% 2.5.0 and earlier 2.5.1 September 27, 2023
CVE-2026-39488 Medium 4.3 0.2% 4.0.2 and earlier 4.0.3 March 26, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.