« Volver al listado

Wpeasycart

Wpeasycart WP Easycart: vulnerabilidades y CVE

Wpeasycart WP Easycart tiene 15 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses3
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94124Alta (8.5)0.22%—23 sept 2026
Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
CVE-2026-17553Alta (7.2)0.43%—9 sept 2026
The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and…
CVE-2026-57765Alta (8.5)0.36%—2 jul 2026
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
CVE-2024-35667Media (5.3)0.38%—11 jun 2024
Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.
CVE-2024-32452Media (5.4)0.21%—15 abr 2024
Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.
CVE-2023-3023Alta (7.2)0.70%—12 jul 2023
The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of…
CVE-2023-2896Media (4.3)0.24%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function.…
CVE-2023-2895Media (4.3)0.24%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product…
CVE-2023-2894Media (4.3)0.24%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product…
CVE-2023-2893Media (4.3)0.24%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function.…
CVE-2023-2892Media (4.3)0.23%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function.…
CVE-2023-2891Media (4.3)0.24%—9 jun 2023
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This…
CVE-2023-1124Alta (7.2)1.1%—3 abr 2023
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
CVE-2015-2673Alta (8.8)19%—6 oct 2017
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator…
CVE-2014-9308Media (6.5)51%—15 ene 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1005 Data from Local System2
  3. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wpeasycart