The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.
We have discovered 7,672 live websites that are affected by CVE-2026-14332.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 7,672 live websites (100% of Ecwid Ecommerce Shopping Cart install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 142 versions ( 100% of all versions) |
| 3,958 websites | |
| 586 websites | |
| 407 websites | |
| 270 websites | |
| 258 websites | |
| 224 websites | |
| 221 websites | |
| 200 websites | |
| 152 websites | |
| 138 websites |
| .com | 4,256 websites |
| .org | 522 websites |
| .de | 330 websites |
| .co.uk | 250 websites |
| .com.au | 202 websites |
| .net | 178 websites |
| .nl | 168 websites |
| .ca | 160 websites |
| .ch | 130 websites |
| .it | 124 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.org | **,*** | ||
| *******.org | **,*** | ||
| ********.at | **,*** | ||
| ***********.org | **,*** | ||
| *********.com | **,*** | ||
| *************************.org | ***,*** | ||
| ******************.***.au | ***,*** | ||
| *************.de | ***,*** | ||
| ****.org | ***,*** | ||
| ************.org | ***,*** |
FAQ