PT-2017-6662 · WordPress · Thecartpress Ecommerce Shopping Cart

Published

2017-12-29

·

Updated

2018-10-09

·

CVE-2015-3302

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TheCartPress eCommerce Shopping Cart plugin for WordPress versions prior to 1.3.9.3
Description The issue allows remote attackers to obtain sensitive order detail information due to a broken authentication mechanism.
Recommendations For versions prior to 1.3.9.3, update to version 1.3.9.3 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3302

Affected Products

Thecartpress Ecommerce Shopping Cart