Record summary

CVE-2019-25152 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 11, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Abandoned Cart Pro for WooCommerce

Browse TYCHE / Abandoned Cart Pro for WooCommerce

Default status: unaffected

CVE ListThrough 7.12.0affected

Default status: unaffected

CVE List, VulnCheckBefore 5.2.0affected

Nuclei templates

1
ProjectDiscoveryHIGHAbandoned Cart Lite for WooCommerce < 5.2.0 - Cross-Site ScriptingCVSS 7.2

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping.

Impact

This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.

Remediation

Fixed in 5.2.0

AuthorsDhiyaneshDK
Template tagscvecve2019wpscanwordpresswpwp-pluginwoocommerce-abandoned-cartxsspassivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:tychesoftwares:abandoned_cart_lite_for_woocommerce:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/woocommerce-abandoned-cart/"
FOFA: body="/wp-content/plugins/woocommerce-abandoned-cart/"

Source: ProjectDiscovery

References

5