WordPress Plugin Vulnerabilities
Ecwid Ecommerce Shopping Cart < 6.12.5 - Cross-Site Request Forgery
Description
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.4. This is due to missing nonce validation on several functions hooked via AJAX in the ~/includes/class-ecwid-admin-storefront-page.php. This makes it possible for unauthenticated attackers to modify several of the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2023-6292 may be a duplicate of this issue.
Affects Plugins
References
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Brandon James Roldan (tomorrowisnew)
Verified
No
WPVDB ID
Timeline
Publicly Published
2023-11-28 (about 2 years ago)
Added
2024-01-04 (about 2 years ago)
Last Updated
2024-02-06 (about 2 years ago)