CVE-2019-25152
Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting
Record summary
CVE-2019-25152 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 11, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Abandoned Cart Pro for WooCommerceBrowse TYCHE / Abandoned Cart Pro for WooCommerceDefault status: unaffected | CVE List | Through 7.12.0 | affected |
Abandoned Cart Lite for WooCommerceBrowse tychesoftwares / Abandoned Cart Lite for WooCommerceDefault status: unaffected | CVE List, VulnCheck | Before 5.2.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHAbandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site ScriptingCVSS 7.2
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping.
Impact
This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.
Remediation
Fixed in 5.2.0
Source: ProjectDiscovery