CVE Database /
CVE-2022-2432
CVE · Medium
CVE-2022-2432 — Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2432
|
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.10.24 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 6.10.24
|
6.10.24 |
2022-07-11 |
—
|
CVE-2022-2432
The Ecwid Ecommerce Shopping Cart plugin for WordPress through version 6.10.23 contains a cross-site request forgery vulnerability stemming from insufficient nonce verification in the ecwid_update_plugin_params function. An unauthenticated attacker could exploit this flaw to modify plugin settings if they successfully deceive an administrator into clicking a malicious link. The vulnerability was patched in version 6.10.24.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings