Cross-Site Request Forgery Vulnerability in Cart66 Lite Plugin for WordPress
CVE-2013-5977
Currently unrated
Summary
A vulnerability in the Cart66 Lite plugin for WordPress allows remote attackers to exploit CSRF weaknesses, enabling unauthorized actions by hijacking the authentication of administrators. Specifically, this can lead to manipulation of product details or execution of cross-site scripting (XSS) attacks through fields such as the product name or price description during a product save action. Version 1.5.1.14 and earlier are particularly susceptible to this issue, which highlights the necessity for prompt updates and security measures.
References
Timeline
Vulnerability published
Vulnerability Reserved