CVE-2024-1516
28.02.2024, 09:15
The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.Enginsight
Vendor | Product | Version |
---|---|---|
wp-ecommerce | wp-e-commerce | 𝑥 ≤ 3.15.1 |
zao | wp_ecommerce | 𝑥 ≤ 3.15.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References