cleantalk
Vulnerabilities and Security Researches

Shopping Cart & eCommerce Store, 994186eaba9b0a79052c7543754f7fda7fe33870

Published on
Apr 15, 2022
Research Description
Shopping Cart &amp; eCommerce Store [wp-easycart] < 5.3.0 Shopping Cart & eCommerce Store <= 5.2.6 - Cross-Site Request Forgery The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the 'wp-easycart-submit-newsletter' function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown.
Affected versions
max 5.3.0.
Status
vulnerable