Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-3301. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in TheCartPress WordPress plugin, including local file inclusion, stored XSS, and improper access control. It provides proof-of-concept code for exploiting these vulnerabilities, such as directory traversal via 'tcp_box_path' and XSS via unsanitized input fields.
Description
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in TheCartPress WordPress plugin, including local file inclusion, stored XSS, and improper access control. It provides proof-of-concept code for exploiting these vulnerabilities, such as directory traversal via 'tcp_box_path' and XSS via unsanitized input fields.