The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/229b93cd-544b-4877-8d9f-e6debda9511c | third party advisory vdb entry exploit technical description |