CVE-2023-51533
The Ecwid Ecommerce Shopping Cart plugin for WordPress up to version 6.12.4 contains a cross-site request forgery vulnerability affecting multiple AJAX functions in the admin storefront page component. Because proper nonce verification is not implemented on these functions, attackers can craft malicious requests to alter plugin configuration settings if they successfully convince a site administrator to visit a specially crafted link. This flaw allows unauthenticated actors to compromise plugin functionality without direct access to the WordPress dashboard.
Based on public CVE data (MITRE/NVD).