Input validation vulnerability in Easy PayPal Shopping Cart 1.1.9

The Easy PayPal Shopping Cart for WordPress is vulnerable to a security issue known as Cross-Site Request Forgery. This means that anyone who has access to the plugin settings could potentially add malicious web scripts without needing to authenticate themselves. This could be done if they were able to trick a site administrator into clicking a link. Versions of the plugin up to, and including, 1.1.9 are vulnerable to this issue due to insufficient validation on the wpepsc_plugin_options function.

Detected in:

Easy PayPal Shopping Cart fixed vulnerable versions: >= * <= 1.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.