Levelfourdevelopment maintains a WordPress e-commerce plugin (WP EasyCart) with a narrow but focused vulnerability footprint centered on information-disclosure issues, where sensitive data handling represents the recurring exposure pattern. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Levelfourdevelopment over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57765HIGH Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. | Jul 2, 2026 | 8.5 | 37 | NO | NO |
CVE-2014-4942MEDIUM The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls | Jul 11, 2014 | 5.0 | 29 | NO | YES |
CVE-2026-32422HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This i | Mar 13, 2026 | 8.5 | 27 | NO | NO |
CVE-2025-62997MEDIUM Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCa | Dec 9, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Levelfourdevelopment.
Media articles that mention a CVE ID that affects a product developed by Levelfourdevelopment — matched by CVE ID, not by vendor name.