CVE · Medium

CVE-2024-13795 — Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13795 Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28 Cross-Site Request Forgery (CSRF) Medium 4.3 < 6.12.28 6.12.28 2025-02-17

CVE-2024-13795

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress through version 6.12.27 contains a cross-site request forgery vulnerability in the ecwid_deactivate_feedback() function due to inadequate nonce verification. An unauthenticated attacker could exploit this flaw to submit deactivation messages impersonating a site administrator if they successfully convince an admin to click a malicious link. The vulnerability affects all versions prior to 6.12.28.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.