WP e-Commerce – Store Exporter <= 1.6.6 - Missing Authorization
criticalThe WP e-Commerce – Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpsc_get_action() function in versions up to, and including 1.6.6. This makes it possible for unauthenticated attackers to gain access to restricted actions that allow them to update th...
- CVSS:
- 9.8
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Feb 15, 2016