ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Welcart Plugin <= 1.2.1 - CSRF

Product
Welcart
Description
Because of this vulnerability, the attackers can hijack the authentication of arbitrary users for requests that complete a purchase.
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
CVE Mitre
CVE
Name CVE-2012-5178
Versions
Affected In <= 1.2.1
Fixed In 1.2.2
Disclosure date
2012-09-26
Credits
Yoshinori Matsumoto