The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-04-03T14:38:26.671Z

Updated: 2024-08-02T05:32:46.390Z

Reserved: 2023-03-01T15:20:23.290Z

Link: CVE-2023-1124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-04-03T15:15:18.970

Modified: 2023-11-07T04:02:33.200

Link: CVE-2023-1124

cve-icon Redhat

No data.