CVE-2015-2673
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.93% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- wpeasycart/wp easycart
- Source
- cve@mitre.org
References
- http://blog.rastating.com/wp-easycart-privilege-escalation-information-disclosure/Exploit, Third Party Advisory
- http://blog.rastating.com/wp-easycart-privilege-escalation-information-disclosure/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.