The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options granted they can trick a site administrator into performing an action such as clicking on a link.
References
Configurations
Information
Published : 2022-09-06 11:15
Updated : 2022-09-08 19:58
NVD link : CVE-2022-2432
Mitre link : CVE-2022-2432
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
lightspeedhq
- ecwid_ecommerce_shopping_cart