plugin

Api2Cart Bridge Connector Vulnerabilities

2 known security issues reported for the Api2Cart Bridge Connector WordPress plugin. Most recent disclosed Oct 28, 2022.

2 critical

Running Api2Cart Bridge Connector on your site? Check whether your installed version is affected.

Scan your site free

Api2Cart Bridge Connector <= 1.1.0 - Arbitrary File Upload

critical

The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect file type validation in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code exec...

CVSS:
9.8
Affected:
1.1.0 – 1.1.0
Fixed in:
1.2.0
Disclosed:
Oct 28, 2022

CVE-2022-42698 on NVD →

Api2Cart Bridge Connector <= 1.1.0 - Arbitrary Code Execution

critical

The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.0. This allows unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 1.1.0
Fixed in:
1.2.0
Disclosed:
Oct 28, 2022

CVE-2022-42497 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database