WordPress · Surecart · CVE-2026-57313
**Name of the Vulnerable Software and Affected Versions**
SureCart versions prior to 4.2.3
**Description**
Cross Site Scripting (XSS) exists, allowing users with subscriber privileges to execute malicious scripts in the browser of other users.
**Recommendations**
Update to a version newer than 4.2.2.