Shopping Cart & eCommerce Store, 994186eaba9b0a79052c7543754f7fda7fe33870
- CVE, Research URL
- Home page URL
- Application
- Published on
- Apr 15, 2022
- Research Description
- Shopping Cart & eCommerce Store [wp-easycart] < 5.3.0 Shopping Cart & eCommerce Store <= 5.2.6 - Cross-Site Request Forgery The WP Easycart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the 'wp-easycart-submit-newsletter' function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown.
- Affected versions
-
max 5.3.0.
- Status
-
vulnerable