WordPress Plugin Vulnerabilities
WP EasyCart < 5.4.9 - Product Deletion via CSRF
Description
The plugin does not properly implement nonce validation on the process_delete_product function, leading to a Cross-Site Request Forgery vulnerability.
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Alex Thomas
Verified
No
WPVDB ID
Timeline
Publicly Published
2023-05-27 (about 2 years ago)
Added
2023-06-09 (about 2 years ago)
Last Updated
2023-06-09 (about 2 years ago)