Description
WordPress Plugin TheCartPress eCommerce Shopping Cart is prone to a security bypass vulnerability because the application fails to properly check user credentials. An attacker can exploit this issue to obtain sensitive information which may help in launching further attacks. WordPress Plugin TheCartPress eCommerce Shopping Cart version 1.1.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.0 or latest
References
Related Vulnerabilities
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.6.7)
WordPress Plugin CopySafe PDF Protection Arbitrary File Upload (0.6)
WordPress Plugin ENL Newsletter SQL Injection (1.0.1)
Joomla! Core 3.0.x Cross-Site Scripting (3.0.0 - 3.0.3)
WordPress Plugin WordPress Leads Cross-Site Scripting (1.6.2)