PT-2023-16772 · WordPress · Shopping Cart & Ecommerce Store
Shreya Pohekar
·
Published
2023-04-03
·
Updated
2025-02-14
·
CVE-2023-1124
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Shopping Cart & eCommerce Store WordPress plugin versions prior to 5.4.3
Description
The issue allows authenticated users with admin privileges to perform Local File Inclusion (LFI) attacks due to a lack of validation of HTTP requests. LFI attacks involve tricking an application into accessing or including files on the server that it should not, potentially leading to sensitive information disclosure or code execution.
Recommendations
For versions prior to 5.4.3, update to version 5.4.3 or later to resolve the issue. As a temporary workaround, consider restricting admin privileges to trusted users only until the update can be applied.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopping Cart & Ecommerce Store