Cross-site Scripting Vulnerability in WP-OliveCart by WP-OliveCart
CVE-2016-4903
6.1MEDIUM
Summary
The vulnerability in WP-OliveCart prior to version 3.1.3 and WP-OliveCartPro prior to version 3.1.8 allows remote adversaries to execute arbitrary web scripts or HTML code. This occurs through various unspecified vectors, potentially jeopardizing user session integrity and exposing sensitive data. It is crucial for users to update to the latest versions to mitigate these security risks.
Affected Version(s)
WP-OliveCart versions prior to 3.1.3
WP-OliveCartPro versions prior to 3.1.8
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved