Shopping Cart & eCommerce Store, 9acfa4f2-8e7a-4d4f-b33d-9162cd81365e
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- WP EasyCart: Shopping Cart and eCommerce Store [wp-easycart] < 5.2.5 Shopping Cart & eCommerce Store < 5.2.5 - Arbitrary Design Settings Update via CSRF The plugin is lacking CSRF checks in various AJAX actions, such as ec_admin_ajax_save_design_settings, which could allow attackers to make a logged in admin update arbitrary settings
- Affected versions
-
max 5.2.5.
- Status
-
vulnerable