Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
CVE-2026-94124 at the National Vulnerability Database