Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-3302. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in TheCartPress WordPress plugin, including local file inclusion, stored XSS, and improper access control. It provides proof-of-concept code for exploiting these vulnerabilities, such as directory traversal via 'tcp_box_path' and XSS via unsanitized input fields.
Description
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
Exploits (1)
The exploit demonstrates multiple vulnerabilities in TheCartPress WordPress plugin, including local file inclusion, stored XSS, and improper access control. It provides proof-of-concept code for exploiting these vulnerabilities, such as directory traversal via 'tcp_box_path' and XSS via unsanitized input fields.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N