WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Simple Shopping Cart

Lightweight, user-friendly plugin to sell products/services on WordPress. Easily add a shopping cart and start accepting orders in minutes.

12Reported vulnerabilities
8.2Highest CVSS score
5.3.2Latest version
10,000+Active installs

What to do now

Update Simple Shopping Cart to 5.3.0 or later. 12 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-4672 Medium 5.4 0.5% Before 4.6.2 4.6.2 January 23, 2023
CVE-2025-3529 High 8.2 0.4% 0 to 5.1.2 (inclusive) 5.1.3 April 23, 2025
CVE-2025-3530 High 7.5 0.5% 0 to 5.1.2 (inclusive) 5.1.3 April 23, 2025
CVE-2013-2705 Medium 6.8 1.1% 3.5 and earlier
1.2 to 1.2 (inclusive)
1.2.2 to 1.2.2 (inclusive)
1.3 to 1.3 (inclusive)
1.4 to 1.4 (inclusive)
1.5 to 1.5 (inclusive)
1.6 to 1.6 (inclusive)
1.7 to 1.7 (inclusive)
1.8 to 1.8 (inclusive)
1.9 to 1.9 (inclusive)
2.0 to 2.0 (inclusive)
2.1 to 2.1 (inclusive)
2.2 to 2.2 (inclusive)
2.3 to 2.3 (inclusive)
2.4 to 2.4 (inclusive)
2.5 to 2.5 (inclusive)
2.6 to 2.6 (inclusive)
2.8 to 2.8 (inclusive)
3.2.7 to 3.2.7 (inclusive)
3.2.8 to 3.2.8 (inclusive)
3.2.9 to 3.2.9 (inclusive)
3.3.0 to 3.3.0 (inclusive)
3.3.1 to 3.3.1 (inclusive)
3.3.2 to 3.3.2 (inclusive)
3.4 to 3.4 (inclusive)
3.6 May 13, 2014
CVE-2025-3874 Medium 6.5 0.4% Before 5.1.4 5.1.4 May 1, 2025
CVE-2024-12622 Medium 6.4 0.4% 0 to 5.0.7 (inclusive) 5.0.8 December 24, 2024
CVE-2026-0552 Medium 6.4 0.2% 0 to 5.2.4 (inclusive) 5.2.5 April 4, 2026
CVE-2025-3890 Medium 5.4 0.3% Before 5.1.4 5.1.4 May 1, 2025
CVE-2023-1431 Medium 5.3 0.5% 4.6.3 and earlier 4.6.4 March 16, 2023
CVE-2026-48868 Medium 5.3 0.3% 5.2.9 and earlier 5.3.0 June 2, 2026
CVE-2025-3889 Medium 5.3 0.3% Before 5.1.4 5.1.4 May 1, 2025
CVE-2023-6497 Medium 4.8 0.3% 4.7.1 and earlier 4.7.2 January 27, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.