Input validation vulnerability in Ready! Ecommerce Shopping Cart 0.5.1

The Ready! Ecommerce Shopping Cart plugin for WordPress was vulnerable to Cross-Site Request Forgery and Cross-Site Scripting in versions before 0.5.1. This means that if an unauthenticated attacker could trick a site administrator into clicking on a link or performing some other action, they could make unauthorized AJAX calls and perform arbitrary actions. This was due to the lack of proper nonce validation on several functions.

Detected in:

Ready! Ecommerce Shopping Cart open vulnerable versions: >= * < 0.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.