CVE-2022-2432
published 2022-09-06CVE-2022-2432: The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to…
PriorityP416medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.45%
36.2th percentile
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options granted they can trick a site administrator into performing an action such as clicking on a link.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ecwid | ecwid_ecommerce_shopping_cart | 6.10.23 – 6.10.23 | — |
| lightspeedhq | ecwid_ecommerce_shopping_cart | <= 6.10.23 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2755658%40ecwid-shopping-cart%2Ftrunk&old=2754114%40ecwid-shopping-cart%2Ftrunk&sfp_email=&sfph_mail=https://www.wordfence.com/blog/2022/08/cross-site-request-forgery-vulnerability-patched-in-ecwid-ecommerce-shopping-cart-plugin/https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2755658%40ecwid-shopping-cart%2Ftrunk&old=2754114%40ecwid-shopping-cart%2Ftrunk&sfp_email=&sfph_mail=https://www.wordfence.com/blog/2022/08/cross-site-request-forgery-vulnerability-patched-in-ecwid-ecommerce-shopping-cart-plugin/
2022-09-06
Published