Simple Shopping Cart (WP Simple Shopping Cart) is a widely used WordPress plugin that adds a PayPal and Stripe shopping cart to a site, with more than 2 million downloads and about 10,000 active installations. During security testing a stored Cross-Site Scripting flaw was found and assigned CVE-2026-104119: the plugin did not escape the values of its PayPal API credentials settings fields before printing them back on its admin pages. A high-privilege user can store JavaScript there that executes whenever the settings page is opened — including on setups where administrators are not allowed to post raw HTML, such as WordPress Multisite. All versions below 5.2.6 are affected; the issue is fixed in 5.2.6.

CVECVE-2026-104119
Simple Shopping Cart < 5.2.6
All Time2 085 537
Active installations10 000+
Publicly PublishedOctober 2, 2026
Last UpdatedOctober 2, 2026
ResearcherKrugov Artyom
OWASP TOP-10A03:2021 – Injection (Cross-Site Scripting)
CWECWE-79
PoCYes
ExploitNo
Referencehttps://www.cve.org/CVERecord?id=CVE-2026-104119
https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/
Plugin Security Certification by CleanTalkNot safe
Logo of the pluginSimple Shopping Cart plugin logo

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Timeline

January 20, 2026Plugin testing and vulnerability detection in the Simple Shopping Cart have been completed
January 20, 2026I contacted the author of the plugin and provided a vulnerability PoC with a description and recommendations for fixing
October 2, 2026Registered CVE-2026-104119

Discovery of the Vulnerability

While auditing the admin settings screens of the Simple Shopping Cart plugin, I found that the fields of the new PayPal PPCP settings interface — in particular the Live Secret Key field under API Credentials — are saved as typed and later written back into the page without output escaping. The vendor’s own changelog for version 5.2.6 describes the fix in the same terms: added output escaping to the new PayPal API settings interface fields. Because the stored value is printed straight into the HTML of the settings page, a value that closes the surrounding attribute or tag turns into executable markup that is saved in the database and runs every time the page is opened — a persistent (Stored) XSS.

Understanding of Stored XSS attacks

Stored (persistent) Cross-Site Scripting keeps the attacker’s payload on the server so it is served automatically to whoever opens the affected page. This case needs an Administrator account, which is why the CVSS score is Low on a standard single site — an administrator there can already post raw HTML through the unfiltered_html capability. The risk becomes real on WordPress Multisite and hardened installations where site administrators do not hold unfiltered_html: missing output escaping lets them bypass that restriction and run JavaScript in the context of other administrators, including network-level ones.

A shopping-cart plugin raises the stakes further: its settings page is where payment-related credentials live, and an administrator who opens it with a script running in the page can have the session abused or the displayed configuration read by the attacker.

Exploiting the Stored XSS Vulnerability

To reproduce the vulnerability on an affected version (below 5.2.6):

  • Log in as an Administrator (on Multisite, a sub-site administrator without unfiltered_html) and open the Simple Cart menu.
  • Go to Settings.
  • Select PayPal PPCP and open API Credentials.
  • Insert the XSS payload into the Live Secret Key field and save the settings.
  • Reload the settings page and move the mouse over the field — the stored value is printed without escaping and the injected handler executes.

PoC payload placed in the Live Secret Key field:

333"test=' onmouseover=alert(779) test=' //

The payload closes the HTML attribute the stored value is printed into and adds an onmouseover handler, so alert(779) runs in the context of the admin page. In a real attack the harmless alert() would be replaced with code that creates a rogue administrator or steals the session — and, because it sits on the page that holds payment settings, it runs exactly where a site owner is most likely to be looking.

Recommendations for Improved Security

To mitigate CVE-2026-104119:

  • Update Simple Shopping Cart to version 5.2.6 or later immediately (the current release is newer still).
  • Escape every stored setting on output with esc_attr() / esc_html() — even settings that only administrators can edit.
  • Do not treat the administrator role as a trust boundary for HTML, especially on Multisite where unfiltered_html is disallowed for site administrators.
  • Limit the number of administrator accounts and protect them with 2FA, so a single compromised admin cannot plant persistent payloads.
  • Implement a strong Content Security Policy (CSP) to block inline JavaScript execution.
  • Deploy a Web Application Firewall to filter XSS payloads before they reach the application.

To prevent this type of attack, follow our methods of XSS prevention.

By addressing Stored XSS vulnerabilities like CVE-2026-104119 early, WordPress site owners and plugin developers can protect administrators and entire networks from account takeover. Stay vigilant, stay secure.

#WordPressSecurity #StoredXSS #SimpleShoppingCart #WebsiteSafety #StayProtected

Use CleanTalk solutions to improve the security of your website

Krugov Artyom
CVE-2026-104119 – Simple Shopping Cart – Admin+ Stored XSS via PayPal API Credentials – PoC

Artyom Krugov

Cybersecurity Specialist with 4 years of hands-on experience in web application and WordPress security. Holder of the OSCP+ certification and author of 80+ publicly disclosed CVEs affecting WordPress plugins and themes. Specialized in vulnerability research, penetration testing, website incident response, malware removal, and security hardening of production environments. Experienced in identifying and validating high-impact vulnerabilities in WordPress plugins, themes, and custom web applications, as well as providing practical remediation guidance to improve overall security posture. Strong background in web application security, source code review, vulnerability assessment, exploit validation, and post-compromise recovery of infected websites.

Visit Author's Website

See all posts by krugov-artyom

Leave a Reply

Your email address will not be published. Required fields are marked *