plugin

Mini Cart Vulnerabilities

5 known security issues reported for the Mini Cart WordPress plugin. Most recent disclosed Nov 11, 2023.

1 high

Running Mini Cart on your site? Check whether your installed version is affected.

Scan your site free

MiniCart [mini-cart] < 1.00.2

unknown

Update the plugin. Lenon Leite discovered and reported this SQL Injection vulnerability in WordPress Mini Cart Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.00.2.

Affected:
up to 1.00.2
Fixed in:
1.00.2
Disclosed:
Nov 11, 2023

Mini Cart <= 1.00.1 - Authenticated (Admin+) SQL Injection

high

The Mini Cart plugin for WordPress is vulnerable to SQL Injection via the ‘item’ parameter in versions up to, and including, 1.00.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-leve...

CVSS:
7.2
Affected:
up to 1.00.1
Fix:
No patched version reported
Disclosed:
Nov 11, 2016

MiniCart [mini-cart] < 1.00.2 (closed)

unknown

This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.00.2
Fixed in:
1.00.2
Disclosed:
Nov 11, 2016

MiniCart [mini-cart] <= 1.00.1 (unfixed)

unknown

The Mini Cart plugin for WordPress is vulnerable to SQL Injection via the ‘item’ parameter in versions up to, and including, 1.00.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-leve...

Affected:
up to 1.00.1
Fix:
No patched version reported
Disclosed:
Nov 11, 2016

MiniCart [mini-cart] <= 1.00.1 (unfixed + closed)

unknown

$_REQUEST[item] is not escaped. Url is accessible for user collaborator above. Url vulnerable : http://target/wp-admin/edit.php?page=mini-cart/item_form.php&amp;item=0&amp;action=edit

Affected:
up to 1.00.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database