CVE-2026-2019 | Cart All In One for WooCommerce Plugin up to 1.1.21 on WordPress eval sc_assign_page code injection
A vulnerability was found in Cart All In One for WooCommerce Plugin up to 1.1.21 on WordPress. It has been rated as critical. This affects the function eval. This manipulation of the argument sc_assign_page causes code injection.
This vulnerability is handled as CVE-2026-2019. The attack can be initiated remotely. There is not any exploit available.