Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure
Summary
| CVE | CVE-2024-4213 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-14 15:43:06 UTC |
| Updated | 2026-04-08 18:21:42 UTC |
| Description | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Problem Types: CWE-922 | CWE-922 CWE-922 Insecure Storage of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Levelfourstorefront | Shopping Cart ECommerce Store | affected 5.6.4 semver | Not specified |
| ADP | Levelfourstorefront | Shopping Cart Ecommerce Store | affected 5.6.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| plugins.trac.wordpress.org/changeset/3084202/wp-easycart/trunk/admin/inc/wp_easycart_adm... | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | |
| www.wordfence.com/threat-intel/vulnerabilities/id/93daab72-1243-4a05-91d3-9254a... | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: rajesh patil (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-05-10T09:18:19.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.