PT-2023-16978 · WordPress · Wp Simple Shopping Cart

Ayoub Safa

·

Published

2023-03-16

·

Updated

2023-03-22

·

CVE-2023-1431

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Simple Shopping Cart plugin for WordPress versions up to, and including, 4.6.3
Description The issue allows unauthenticated attackers to view sensitive information that should be limited to administrators only. This information can include first name, last name, email, address, IP Address, and more. The problem arises because the plugin saves shopping cart data exports in a publicly accessible location, specifically at the /wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/ endpoint.
Recommendations For WP Simple Shopping Cart plugin for WordPress versions up to, and including, 4.6.3, consider restricting access to the /wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/ endpoint until a patch is available. As a temporary workaround, avoid using the plugin's data export feature to minimize the risk of sensitive information exposure. Update to a version later than 4.6.3 when available.

Fix

Related Identifiers

CVE-2023-1431

Affected Products

Wp Simple Shopping Cart