Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Lightspeedhq Subscribe
Filtered by product Ecwid Ecommerce Shopping Cart
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24377 1 Lightspeedhq 1 Ecwid Ecommerce Shopping Cart 2023-02-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
CVE-2022-2432 1 Lightspeedhq 1 Ecwid Ecommerce Shopping Cart 2022-09-08 N/A 4.3 MEDIUM
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options granted they can trick a site administrator into performing an action such as clicking on a link.