CVE-2026-14332

Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.


We have discovered 7,672 live websites that are affected by CVE-2026-14332.

Run a Free Instant Scan




Affected Software

Product  Ecwid Ecommerce Shopping Cart
Category Wordpress Plugins
Vulnerable Domains7,672 live websites (100% of Ecwid Ecommerce Shopping Cart install base)
Vulnerable Versions
  • from 0 through 7.0.9
Vulnerable Versions Count142 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Alexander Jurkschat (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14332
United States3,958 websites



Germany586 websites
GB407 websites
Canada270 websites
Australia258 websites
France224 websites
Netherlands221 websites
Italy200 websites
Switzerland152 websites
Belgium138 websites

Website Distribution by TLD

Number of websites using CVE-2026-14332
.com4,256 websites
.org522 websites
.de330 websites
.co.uk250 websites
.com.au202 websites
.net178 websites
.nl168 websites
.ca160 websites
.ch130 websites
.it124 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14332

Top websites that are affected by CVE-2026-14332. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.org United States**,***
*******.org United States**,***
********.at Austria**,***
***********.org United States**,***
*********.com United States**,***
*************************.org United States***,***
******************.***.au Australia***,***
*************.de United States***,***
****.org United States***,***
************.org United States***,***
See full domain list

FAQ

CVE-2026-14332 is Missing Authorization in Ecwid Ecommerce Shopping Cart
A total of 7,672 websites have been identified as vulnerable to CVE-2026-14332, based on global website indexing conducted by WebTechSurvey.
The Ecwid Ecommerce Shopping Cart is affected by the CVE-2026-14332 vulnerability.
Ecwid Ecommerce Shopping Cart versions up to 7.0.9 are vulnerable to CVE-2026-14332.
CVE-2026-14332 is resolved in version 7.0.9 of Ecwid Ecommerce Shopping Cart.