Access violation vulnerability in WordPress Simple Shopping Cart 5.1.3

The WordPress Simple Shopping Cart plugin has a security issue in all versions up to and including 5.1.3. This vulnerability allows attackers to change the quantity of a product to a negative number, which can result in the product cost being subtracted from the total order cost. However, this only works if the Manual Checkout mode is used, as PayPal and Stripe will not process payments for a negative quantity.

Detected in:

Simple Shopping Cart fixed vulnerable versions:
WordPress Simple Shopping Cart fixed vulnerable versions: >= * <= 5.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.