Input validation vulnerability in Ecwid Ecommerce Shopping Cart 6.12.4

The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This affects all versions of the plugin up to version 6.12.4, and is due to the lack of protection for certain functions that are connected to the plugin. This means that attackers can use a forged request to change the plugin’s settings, as long as they can get a site administrator to perform an action like clicking on a link.

Detected in:

Ecwid by Lightspeed Ecommerce Shopping Cart fixed vulnerable versions:
Ecwid Ecommerce Shopping Cart fixed vulnerable versions: >= * <= 6.12.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.