CVE-2015-2673

HIGH

WP EasyCart 1.1.30-3.0.20 - Unauthenticated Privilege Escalation and RCE via option_name/option_value

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2673. PoCs published by rastating, including Metasploit module auxiliary/admin/http/wp_easycart_privilege_escalation.

AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in the WordPress WP EasyCart plugin by allowing authenticated users to modify system options via unvalidated AJAX functions. It changes the admin email, enables user registration, and sets the default role to administrator, enabling an attacker to create an admin account.

Description

The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.

Exploits (1)

metasploit WORKING POC
by rastating · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/wp_easycart_privilege_escalation.rb

This Metasploit module exploits a privilege escalation vulnerability in the WordPress WP EasyCart plugin by allowing authenticated users to modify system options via unvalidated AJAX functions. It changes the admin email, enables user registration, and sets the default role to administrator, enabling an attacker to create an admin account.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress WP EasyCart plugin versions 1.1.30 to 3.0.20
Auth required
Prerequisites: Valid WordPress credentials · WP EasyCart plugin installed and vulnerable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.6377
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (50)
wpeasycart/wp_easycart 1.1.30
wpeasycart/wp_easycart 1.1.31
wpeasycart/wp_easycart 1.1.32
wpeasycart/wp_easycart 1.1.33
wpeasycart/wp_easycart 1.1.34
wpeasycart/wp_easycart 1.1.35
wpeasycart/wp_easycart 1.1.36
wpeasycart/wp_easycart 1.2.0
wpeasycart/wp_easycart 1.2.1
wpeasycart/wp_easycart 1.2.2
... and 40 more
Published Oct 06, 2017
Tracked Since Feb 18, 2026