What is CVE-2026-14332?
CVE-2026-14332 is a vulnerability in the Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before version 7.0.9. It allows any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline due to missing capability check and nonce verification on a store-management action. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-14332 Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin-in 7.0.9-dan əvvəlki versiyalarında aşkarlanıb. Bu boşluq autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, subscriber) mağaza idarəetmə əməliyyatında capability check və nonce verification olmadığı üçün mağazanı deaktiv etməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does exploiting CVE-2026-14332 require authentication?
Yes, the vulnerability can only be exploited by any authenticated user, such as a subscriber.
What is the potential impact of CVE-2026-14332 on an Ecwid by Lightspeed store?
An attacker can disconnect the store and take the storefront offline due to missing capability check and nonce verification on a store-management action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.