The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-cartsguru-event-handler.php.
References
Link | Resource |
---|---|
http://dumpco.re/bugs/wp-plugin-carts-guru-id | Exploit Third Party Advisory |
https://wpvulndb.com/vulnerabilities/9292 |
Configurations
Information
Published : 2019-05-20 13:29
Updated : 2019-05-27 03:29
NVD link : CVE-2019-12241
Mitre link : CVE-2019-12241
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
carts.guru
- carts_guru