7.2

CVE-2019-25152

Exploit

Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting

Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.
Mögliche Gegenmaßnahme
Abandoned Cart Lite for WooCommerce: Update to version 5.2.0, or a newer patched version
Abandoned Cart Pro for WooCommerce: Update to version 7.13.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TychesoftwaresAbandoned Cart Lite For Woocommerce SwPlatformwordpress Version < 5.2.0
TychesoftwaresAbandoned Cart Pro For Woocommerce SwPlatformwordpress Version <= 7.12.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Abandoned Cart Lite for WooCommerce
Version [*, 5.2.0)
SystemWordPress Plugin
Produkt Abandoned Cart Pro for WooCommerce
Version *-7.12.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
security@wordfence.com 7.2 3.9 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://plugins.trac.wordpress.org/changeset/2033212
Patch
https://wpscan.com/vulnerability/9229
Third Party Advisory
https://www.wordfence.com/blog/2019/03/xss-flaw-in-abandoned-cart-plugin-leads-to-wordpress-site-takeovers/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/a9cc5c6d-4396-4ebf-8788-f01dd9e9cfbc?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/a9cc5c6d-4396-4ebf-8788-f01dd9e9cfbc
Third Party Advisory