CVE-2026-8880 | romancartsupport RomanCart Ecommerce Plugin up to 2.0.8 on WordPress Shortcode romancart_button_shortcode blclass cross site scripting (EUVD-2026-35305)
A vulnerability was found in romancartsupport RomanCart Ecommerce Plugin up to 2.0.8 on WordPress. It has been classified as problematic. Affected is the function romancart_button_shortcode of the component Shortcode Handler. Performing a manipulation of the argument blclass results in cross site scripting.
This vulnerability was named CVE-2026-8880. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.