CVE-2015-2673
HIGHWP EasyCart 1.1.30-3.0.20 - Unauthenticated Privilege Escalation and RCE via option_name/option_value
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2673.
PoCs published by rastating, including Metasploit module auxiliary/admin/http/wp_easycart_privilege_escalation.
AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in the WordPress WP EasyCart plugin by allowing authenticated users to modify system options via unvalidated AJAX functions. It changes the admin email, enables user registration, and sets the default role to administrator, enabling an attacker to create an admin account.
Description
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.
Exploits (1)
This Metasploit module exploits a privilege escalation vulnerability in the WordPress WP EasyCart plugin by allowing authenticated users to modify system options via unvalidated AJAX functions. It changes the admin email, enables user registration, and sets the default role to administrator, enabling an attacker to create an admin account.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H