WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
BID:54103
Info
WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
| Bugtraq ID: | 54103 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2012 12:00AM |
| Updated: | Jun 20 2012 12:00AM |
| Credit: | Charlie Eriksen |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
TheCartPress plugin for WordPress is prone to a security-bypass vulnerability because the application fails to properly check user credentials.
An attacker can exploit this issue to obtain sensitive information. This may aid in further attacks.
TheCartPress 1.1.9.2 is vulnerable; other versions may also be affected.
TheCartPress plugin for WordPress is prone to a security-bypass vulnerability because the application fails to properly check user credentials.
An attacker can exploit this issue to obtain sensitive information. This may aid in further attacks.
TheCartPress 1.1.9.2 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
Attackers can exploit this issue through a web browser.
Attackers can exploit this issue through a web browser.
Solution / Fix
WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
Solution:
Updates are available. Please contact the vendor for more information.
Solution:
Updates are available. Please contact the vendor for more information.
References
WordPress TheCartPress Plugin 'PrintOrder.php' Script Security Bypass Vulnerability
References:
References:
- TheCartPress Download Page (Wordpress)