6.8
CVSSv2

CVE-2013-5977

Published: 01/11/2013 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin prior to 1.5.1.15 for WordPress allows remote malicious users to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cart66 cart66 lite plugin 1.1.3

cart66 cart66 lite plugin 1.4.0

cart66 cart66 lite plugin 1.5.0.1

cart66 cart66 lite plugin 1.0.7

cart66 cart66 lite plugin 1.4.9

cart66 cart66 lite plugin 1.4.7

cart66 cart66 lite plugin 1.5.0

cart66 cart66 lite plugin 1.5.1.8

cart66 cart66 lite plugin 1.0.8

cart66 cart66 lite plugin 1.5.1.2

cart66 cart66 lite plugin 1.1.5

cart66 cart66 lite plugin 1.1.4

cart66 cart66 lite plugin 1.4.1

cart66 cart66 lite plugin 1.4.8

cart66 cart66 lite plugin 1.1

cart66 cart66 lite plugin

cart66 cart66 lite plugin 1.1.2

cart66 cart66 lite plugin 1.4.4

cart66 cart66 lite plugin 1.5.0.2

cart66 cart66 lite plugin 1.5.1.1

cart66 cart66 lite plugin 1.1.1

cart66 cart66 lite plugin 1.3.0

cart66 cart66 lite plugin 1.4.2

cart66 cart66 lite plugin 1.1.6

cart66 cart66 lite plugin 1.5.1

Exploits

# Exploit Title: Wordpress Cart66 Plugin 15114 Multiple Vulnerabilities # Exploit Author: absane # Blog: blognoobrootcom # Discovery date: September 29th 2013 # Vendor notified: September 29th 2013 # Vendor fixed: October 2 2013 # Vendor Homepage: cart66com # Software Link: downloadswo ...
WordPress Cart66 plugin version 15114 suffers from cross site request forgery and cross site scripting vulnerabilities ...