WordPress Plugin Vulnerabilities

RestroPress < 2.8.3 - Cart Manipulation via CSRF

Description

The plugin does not properly check for CSRF in some of its AJAX calls, allowing attackers to make users do unwanted actions, such as add arbitrary products to their cart, or empty it completely

Proof of Concept

Affects Plugins

Fixed in 2.8.3

Classification

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-07-19 (about 4 years ago)
Added
2021-07-19 (about 4 years ago)
Last Updated
2021-07-19 (about 4 years ago)

Other