TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Unauthenticated Privilege Escalation
critical
The TheCartPress eCommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.3.6. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.5.3.6
- Fix:
- No patched version reported
- Disclosed:
- May 10, 2026
CVE-2021-47932 on NVD →
TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Sensitive Information Disclosure
high
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
- CVSS:
- 7.5
- Affected:
- up to 1.5.3.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2015
CVE-2015-3302 on NVD →
TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company, (4...
- CVSS:
- 6.1
- Affected:
- up to 1.5.3.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2015
CVE-2015-3300 on NVD →
TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Directory Traversal
medium
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin...
- CVSS:
- 4.9
- Affected:
- up to 1.5.3.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 29, 2015
CVE-2015-3301 on NVD →
TheCartPress eCommerce Shopping Cart <= 1.5.3.6 Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_p...
- CVSS:
- 8.8
- Affected:
- up to 1.5.3.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 8, 2015
CVE-2015-3986 on NVD →
TheCartPress eCommerce Shopping Cart <= 1.1.5 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Dec 31, 2011
CVE-2011-5207 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database