plugin

Simple E Commerce Shopping Cart Vulnerabilities

5 known security issues reported for the Simple E Commerce Shopping Cart WordPress plugin. Most recent disclosed Dec 7, 2024.

1 high 2 medium

Running Simple E Commerce Shopping Cart on your site? Check whether your installed version is affected.

Scan your site free

Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal [simple-e-commerce-shopping-cart] <= 3.1.2 (unfixed + closed)

unknown

[en] The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible...

Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Dec 7, 2024

CVE-2024-12128 on NVD →

Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal [simple-e-commerce-shopping-cart] <= 3.1.2 (unfixed + closed)

unknown

[en] The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for auth...

Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Dec 7, 2024

CVE-2024-12253 on NVD →

Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Reflected Cross-Site Scripting via monthly_sales_current_year Parameter

medium

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for u...

CVSS:
6.1
Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Dec 6, 2024

CVE-2024-12128 on NVD →

Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update / Data Access

medium

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for authentic...

CVSS:
5.4
Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Dec 6, 2024

CVE-2024-12253 on NVD →

Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Cross-Site Request Forgery

high

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.2. This is due to missing nonce validation on the simpleecommcart-products page, and missing file type validation on the Downloadable Digital...

CVSS:
8.8
Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

CVE-2021-24620 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database