EasyCart 1.1.30 - 3.0.20 - Privilege Escalation
2015-02-26 00:00
rastatingStrategic Overview
StatusPatched in 3.0.21
Affected PluginShopping Cart & eCommerce Store
Affected Version
1.1.30 – 3.0.20CVSS8.8High
CVE
CVE-2015-2673Vulnerability Overview
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.
Technical Analysis
REMEDIATION: Update to version 3.0.21, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C