Cross-Site Scripting Vulnerabilities in TheCartPress eCommerce Plugin for WordPress
CVE-2015-3300
Currently unrated
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 14 May 2015
What is CVE-2015-3300?
TheCartPress eCommerce Shopping Cart plugin for WordPress is susceptible to multiple cross-site scripting vulnerabilities that permit remote attackers to inject arbitrary web scripts or HTML. This exploit can occur through various input parameters during checkout and within the administrative interfaces, such as billing and shipping details. Attackers can leverage these vulnerabilities to execute malicious scripts, potentially compromising the security of the website and its users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved