
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1750 is a privilege escalation vulnerability in the Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress, affecting all versions up to and including 7.0.7. The flaw allows authenticated attackers with minimal permissions (e.g., subscriber-level) to escalate their privileges to store manager access. It was published on February 15, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Wordfence).
The root cause is a missing capability check (CWE-269: Improper Privilege Management) in the save_custom_user_profile_fields function of the plugin. An authenticated attacker can supply the ec_store_admin_access parameter during a profile update request, which is accepted without verifying whether the user has the authority to grant themselves elevated permissions. This network-accessible attack requires low privileges and no user interaction, making it straightforward to exploit (Red Hat CVE, Wordfence).
Successful exploitation grants the attacker store manager access to the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. A store manager can access customer data, order information, and payment details, and can modify store configurations, products, and potentially inject malicious content. This could facilitate further lateral movement within the WordPress environment or serve as a stepping stone to full site compromise (Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.03%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It is detectable by Qualys scanner (detection ID: 530962) (Wordfence).
ec_store_admin_access parameter set to grant store manager privileges (e.g., ec_store_admin_access=1).save_custom_user_profile_fields function processes the request without a capability check, applying the elevated ec_store_admin_access role to the attacker's account./wp-admin/admin-ajax.php or profile pages) from subscriber-level accounts containing the ec_store_admin_access parameter.wp_usermeta table, specifically new or modified ec_store_admin_access entries for low-privilege user accounts.Users should update the Ecwid by Lightspeed Ecommerce Shopping Cart plugin to a version beyond 7.0.7 that includes a fix for the missing capability check. Until a patch is applied, site administrators should restrict new user registrations or closely monitor existing low-privilege accounts for suspicious profile update activity. Reviewing and auditing user roles and the ec_store_admin_access meta field in the WordPress database is also recommended (Wordfence, Red Hat CVE).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as a notable privilege escalation issue (Wordfence). The vulnerability was also noted by The Hacker Wire on Mastodon and Bluesky, and covered by Spanish national cybersecurity agencies INCIBE and CCN-CERT, indicating moderate community awareness (INCIBE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."