CVE · Medium

CVE-2023-51533 — Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-51533 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.5 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.12.5 6.12.5 2023-11-28

CVE-2023-51533

The Ecwid Ecommerce Shopping Cart plugin for WordPress up to version 6.12.4 contains a cross-site request forgery vulnerability affecting multiple AJAX functions in the admin storefront page component. Because proper nonce verification is not implemented on these functions, attackers can craft malicious requests to alter plugin configuration settings if they successfully convince a site administrator to visit a specially crafted link. This flaw allows unauthenticated actors to compromise plugin functionality without direct access to the WordPress dashboard.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.