Simple Shopping Cart (WP Simple Shopping Cart) is a widely used WordPress plugin that adds a PayPal and Stripe shopping cart to a site, with more than 2 million downloads and about 10,000 active installations. During security testing a stored Cross-Site Scripting flaw was found and assigned CVE-2026-104119: the plugin did not escape the values of its PayPal API credentials settings fields before printing them back on its admin pages. A high-privilege user can store JavaScript there that executes whenever the settings page is opened — including on setups where administrators are not allowed to post raw HTML, such as WordPress Multisite. All versions below 5.2.6 are affected; the issue is fixed in 5.2.6.
| CVE | CVE-2026-104119 |
| Simple Shopping Cart < 5.2.6 | |
| All Time | 2 085 537 |
| Active installations | 10 000+ |
| Publicly Published | October 2, 2026 |
| Last Updated | October 2, 2026 |
| Researcher | Krugov Artyom |
| OWASP TOP-10 | A03:2021 – Injection (Cross-Site Scripting) |
| CWE | CWE-79 |
| PoC | Yes |
| Exploit | No |
| Reference | https://www.cve.org/CVERecord?id=CVE-2026-104119 https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/ |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Timeline
| January 20, 2026 | Plugin testing and vulnerability detection in the Simple Shopping Cart have been completed |
| January 20, 2026 | I contacted the author of the plugin and provided a vulnerability PoC with a description and recommendations for fixing |
| October 2, 2026 | Registered CVE-2026-104119 |
Discovery of the Vulnerability
While auditing the admin settings screens of the Simple Shopping Cart plugin, I found that the fields of the new PayPal PPCP settings interface — in particular the Live Secret Key field under API Credentials — are saved as typed and later written back into the page without output escaping. The vendor’s own changelog for version 5.2.6 describes the fix in the same terms: added output escaping to the new PayPal API settings interface fields. Because the stored value is printed straight into the HTML of the settings page, a value that closes the surrounding attribute or tag turns into executable markup that is saved in the database and runs every time the page is opened — a persistent (Stored) XSS.
Understanding of Stored XSS attacks
Stored (persistent) Cross-Site Scripting keeps the attacker’s payload on the server so it is served automatically to whoever opens the affected page. This case needs an Administrator account, which is why the CVSS score is Low on a standard single site — an administrator there can already post raw HTML through the unfiltered_html capability. The risk becomes real on WordPress Multisite and hardened installations where site administrators do not hold unfiltered_html: missing output escaping lets them bypass that restriction and run JavaScript in the context of other administrators, including network-level ones.
A shopping-cart plugin raises the stakes further: its settings page is where payment-related credentials live, and an administrator who opens it with a script running in the page can have the session abused or the displayed configuration read by the attacker.
Exploiting the Stored XSS Vulnerability
To reproduce the vulnerability on an affected version (below 5.2.6):
- Log in as an Administrator (on Multisite, a sub-site administrator without
unfiltered_html) and open the Simple Cart menu. - Go to Settings.
- Select PayPal PPCP and open API Credentials.
- Insert the XSS payload into the Live Secret Key field and save the settings.
- Reload the settings page and move the mouse over the field — the stored value is printed without escaping and the injected handler executes.
PoC payload placed in the Live Secret Key field:
333"test=' onmouseover=alert(779) test=' //
The payload closes the HTML attribute the stored value is printed into and adds an onmouseover handler, so alert(779) runs in the context of the admin page. In a real attack the harmless alert() would be replaced with code that creates a rogue administrator or steals the session — and, because it sits on the page that holds payment settings, it runs exactly where a site owner is most likely to be looking.
Recommendations for Improved Security
To mitigate CVE-2026-104119:
- Update Simple Shopping Cart to version 5.2.6 or later immediately (the current release is newer still).
- Escape every stored setting on output with
esc_attr()/esc_html()— even settings that only administrators can edit. - Do not treat the administrator role as a trust boundary for HTML, especially on Multisite where
unfiltered_htmlis disallowed for site administrators. - Limit the number of administrator accounts and protect them with 2FA, so a single compromised admin cannot plant persistent payloads.
- Implement a strong Content Security Policy (CSP) to block inline JavaScript execution.
- Deploy a Web Application Firewall to filter XSS payloads before they reach the application.
To prevent this type of attack, follow our methods of XSS prevention.
By addressing Stored XSS vulnerabilities like CVE-2026-104119 early, WordPress site owners and plugin developers can protect administrators and entire networks from account takeover. Stay vigilant, stay secure.
#WordPressSecurity #StoredXSS #SimpleShoppingCart #WebsiteSafety #StayProtected
Use CleanTalk solutions to improve the security of your website
Krugov Artyom
