Security Advisory

CVE-2015-3986

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-05-14 14:00:00
Last updated 2024-08-06 06:04:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.