Shopping Cart & eCommerce Store, f82e4f8fab10477023dee0b24d6abce9f55aa6fc
- CVE, Research URL
- Home page URL
- Application
- Published on
- Mar 28, 2022
- Research Description
- Shopping Cart & eCommerce Store [wp-easycart] < 5.2.5 Shopping Cart & eCommerce Store <= 5.2.4 - Cross-Site Request Forgery to Settings Update The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.4. This is due to missing or incorrect nonce validation on the 'ec_admin_ajax_save_design_settings' AJAX action. This makes it possible for unauthenticated attackers to change arbitrary design settings on the vulnerable service via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 5.2.5.
- Status
-
vulnerable