CVE-2026-1750Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to supply the 'ec_store_admin_access' parameter during a profile update and gain store manager access to the site.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-15); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-02-15: 5Mentions · 2026-02-17: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-15: 4Technical Details · 2026-02-17: 1Technical Details · 2026-02-20: 102-1502-1702-20
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-155
Disclosure4Patch1
2026-02-171
Disclosure1
2026-02-201
Disclosure1
Full discourse7 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1750 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1750 #CVE-2026-1750 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/AfwLjwbpH0

    Post summary

    The tweet announces CVE‑2026‑1750, a high‑severity WordPress vulnerability, but provides no exploit details, mitigation steps, or evidence of active exploitation.

    0001055
    56 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1750: HIGH] Vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart for WordPress up to v7.0.7 allows attackers to gain store manager access via privilege escalation.#cve,CVE-2026-1750,#cybersecurity https://cvefind.com/CVE-2026-1750

    Post summary

    A new high‑severity privilege‑escalation vulnerability (CVE‑2026‑1750) was disclosed for Ecwid WordPress shopping cart up to v7.0.7, allowing attackers to gain store manager access.

    0001062
    580 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1750 Privilege Escalation in Ecwid WordPress Plugin Allows Unauthorized Store ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1750 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces a new privilege‑escalation vulnerability (CVE-2026-1750) in the Ecwid WordPress plugin, providing only a brief description without any PoC, exploit, or patch details.

    0001045
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1750 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a… https://www.cve.org/CVERecord?id=CVE-2026-1750

    Post summary

    The Ecwid plugin for WordPress is vulnerable to privilege escalation in all versions up to 7.0.7, as identified by CVE‑2026‑1750.

    00010581
    56.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1750 (CVSS:8.8, HIGH) is Awaiting Analysis. The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versio..https://nvd.nist.gov/vuln/detail/CVE-2026-1750 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-1750 is a high‑severity privilege escalation vulnerability in the Ecwid WordPress plugin, currently awaiting analysis with no PoC, exploit or patch disclosed.

    0000025
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1750 - High The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability chec... https://www.thehackerwire.com/vulnerability/CVE-2026-1750/ https://t.co/INkz4mcdAq

    Post summary

    The tweet announces a privilege‑escalation vulnerability (CVE‑2026‑1750) in the Ecwid WordPress plugin affecting versions up to 7.0.7, caused by a missing capability check.

    0000047
    112 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: CVE-2026-1750 lets low-permission users escalate to admin in Ecwid by Lightspeed Shopping Cart for WordPress (all versions ≤7.0.7). Patch ASAP, restrict roles, monitor activity. Details: https://radar.offseq.com/threat/cve-2026-1750-cwe-269-improper-privilege-... https://t.co/VPYol64y3F

    Post summary

    The tweet announces a high‑severity CVE that lets low‑permission users gain admin rights in Ecwid for WordPress, urges immediate patching, and advises role restrictions.

    0000025
    265 followersView on X

Explore more