High severity8.8NVD Advisory· Published May 22, 2017· Updated May 13, 2026
CVE-2016-4904
CVE-2016-4904
Description
Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to hijack the authentication of a user to perform unintended operations via unspecified vectors.
Affected products
4- Olive Design/WP-OliveCartv5Range: versions prior to 3.1.3
- Olive Design/WP-OliveCartProv5Range: versions prior to 3.1.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.wp-olivecart.com/news/20160925.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/93790nvdThird Party AdvisoryVDB Entry
- jvn.jp/en/jp/JVN14567604/index.htmlnvdThird Party AdvisoryVDB Entry
- jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000209.htmlnvdVDB Entry
News mentions
0No linked articles in our index yet.