cleantalk
Vulnerabilities and Security Researches

Inquiry cart, CVE-2024-5155

CVE, Research URL

CVE-2024-5155

Application

Inquiry cart

Published on
Jun 14, 2024
Research Description
The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Affected versions
max 3.4.2.
Status
vulnerable