VYPR

Shopping Cart Ecommerce Store

by WordPress

Source repositories

CVEs (6)

  • CVE-2021-34645HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to…

  • CVE-2024-7827HigAug 20, 2024
    risk 0.50cvss 8.8epss 0.01

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-3211HigApr 12, 2024
    risk 0.50cvss 8.8epss 0.01

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2023-1124HigApr 3, 2023
    risk 0.47cvss 7.2epss 0.01

    The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.

  • CVE-2024-12712MedJan 8, 2025
    risk 0.27cvss 5.3epss 0.00

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order…

  • CVE-2024-4213MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.01

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order…