vendor:
Cart66 Plugin
by:
absane
6.1
CVSS
MEDIUM
CSRF, XSS (Stored)
352
CWE
Product Name: Cart66 Plugin
Affected Version From: 1.5.1.14
Affected Version To: 1.5.1.14
Patch Exists: YES
Related CWE: CVE-2013-5977, CVE-2013-5978
CPE: a:wordpress:cart66:1.5.1.14
Platforms Tested: Wordpress
2013
WordPress Cart66 Plugin 1.5.1.14 Multiple Vulnerabilities
Two vulnerabilities were discovered in the Wordpress plugin Cart66 version 1.5.1.14. The first vulnerability is a Cross-Site Request Forgery (CSRF) vulnerability that allows an authenticated Wordpress admin user to unknowingly add a product or alter an existing product on the site. The second vulnerability is a Stored XSS vulnerability that allows an attacker to inject malicious code into a vulnerable field.
Mitigation:
Update to the latest version of the Cart66 plugin to fix these vulnerabilities. Additionally, it is recommended to implement CSRF protection mechanisms and input validation to prevent similar vulnerabilities in the future.