cleantalk
Vulnerabilities and Security Researches

Shopping Cart & eCommerce Store, CVE-2024-12712

CVE, Research URL

CVE-2024-12712

Published on
Jan 08, 2025
Research Description
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.
Affected versions
max 5.7.9.
Status
vulnerable