Cross-Site Request Forgery Vulnerability in Cart66 Lite Plugin for WordPress
CVE-2013-5977

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 November 2013

Summary

A vulnerability in the Cart66 Lite plugin for WordPress allows remote attackers to exploit CSRF weaknesses, enabling unauthorized actions by hijacking the authentication of administrators. Specifically, this can lead to manipulation of product details or execution of cross-site scripting (XSS) attacks through fields such as the product name or price description during a product save action. Version 1.5.1.14 and earlier are particularly susceptible to this issue, which highlights the necessity for prompt updates and security measures.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.