Vulnerability CVE-2023-1124


Published: 2023-04-03

Description:
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://wpscan.com/vulnerability/229b93cd-544b-4877-8d9f-e6debda9511c

Copyright 2026, cxsecurity.com

 

Back to Top