PT-2026-47674 · WordPress · Romancart Ecommerce
CVE-2026-8880
·
Published
2026-06-09
·
Updated
2026-06-09
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RomanCart Ecommerce versions prior to 2.0.9
Description
The RomanCart Ecommerce plugin for WordPress contains a Stored Cross-Site Scripting issue. This occurs due to insufficient input sanitization and output escaping of user-supplied attributes within the
romancart button shortcode() function. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts via the blclass attribute and other attributes of the 'romancart button' shortcode. These scripts execute whenever a user visits the affected page.Recommendations
Update the plugin to a version later than 2.0.8.
As a temporary mitigation, restrict the ability of users with contributor-level access to use the 'romancart button' shortcode or the
blclass attribute.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Romancart Ecommerce