WP EasyCart
cpe:2.3:a:wpeasycart:wp_easycart:*:*:*:*:wordpress:*:*
- <= 5.7.8
A vulnerability exists in the WP EasyCart Shopping Cart & eCommerce Store plugin for WordPress, in all versions through 5.7.8. The issue arises from a missing capability check on the webhook function, allowing unauthorized users to modify order statuses. This vulnerability could be exploited by unauthenticated attackers to change order statuses without proper authorization.
Exploitation of this vulnerability allows for unauthorized modification of order statuses, which could disrupt the order management process and potentially lead to financial discrepancies.
Users can update to version 5.7.9 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.