
CVE-2026-0552 The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and … https://www.cve.org/CVERecord?id=CVE-2026-0552
Post summary
The passage announces a stored XSS flaw in WordPress's Simple Shopping Cart plugin, describing the affected component and vector, but offers no PoC, exploit code, or patch information.

