Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Shopping Cart & eCommerce Store — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Shopping Cart & eCommerce Store, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Shopping Cart & eCommerce Store product category, focusing on specific vendor advisories and known weakness classifications. It compiles security incidents and software flaws discovered across various online retail platforms and e-commerce management systems within the most recent reporting period, ensuring that the information remains relevant for current threat landscapes and mitigation efforts. The collected data covers a wide spectrum of security issues, ranging from critical remote code execution flaws and SQL injection vulnerabilities to less severe cross-site scripting and authentication bypass issues, providing a comprehensive view of the security posture of digital commerce tools. By exploring this curated collection, users can effectively track individual vendor security advisories to stay informed about patch releases and remediation steps for their specific implementations. Additionally, the page serves as a reference for understanding broader weakness classes, allowing analysts to identify common patterns and root causes associated with vulnerabilities in e-commerce software. Users can also look up a specific product’s vulnerability history to assess long-term security trends, evaluate the reliability of different vendors, and make informed decisions regarding system upgrades or migration strategies. This resource is designed to support security professionals, developers, and business owners in maintaining robust and secure online shopping environments by providing clear, structured, and actionable intelligence on the most pressing threats facing the industry.

Vendor: WP EasyCart

CVE IDTitleCVSSSeverityPublished
CVE-2024-12712 Shopping Cart & eCommerce Store <= 5.7.8 - Missing Authorization to Order Updates CWE-862 5.3 Medium2025-01-08
CVE-2024-7827 Shopping Cart & eCommerce Store <= 5.7.2 - Authenticated (Contributor+) SQL Injection via model_number Parameter CWE-89 8.8 High2024-08-20
CVE-2024-4213 Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure CWE-922 5.3 Medium2024-05-10
CVE-2024-3211 Shopping Cart & eCommerce Store <= 5.6.3 - Authenticated (Contributor+) SQL Injection CWE-89 8.8 High2024-04-12
CVE-2023-3023 WP EasyCart <= 5.4.10 - Authenticated (Administrator+) SQL Injection via 'orderby' CWE-89 7.2 High2023-07-12
CVE-2023-2892 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_delete_product CWE-352 6.5 Medium2023-06-09
CVE-2023-2894 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_deactivate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2893 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_deactivate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2896 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_duplicate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2895 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_bulk_activate_product CWE-352 4.3 Medium2023-06-09
CVE-2023-2891 WP EasyCart <= 5.4.8 - Cross-Site Request Forgery via process_delete_product CWE-352 6.5 Medium2023-06-09
CVE-2023-1124 Shopping Cart & eCommerce Store < 5.4.3 - Admin+ LFI 7.2 -2023-04-03
CVE-2021-34645 Shopping Cart & eCommerce Store <= 5.1.0 Cross-Site Request Forgery to Stored Cross-Site Scripting CWE-352 8.8 High2021-08-19

All 13 known CVE vulnerabilities affecting Shopping Cart & eCommerce Store with full Chinese analysis, references, and POCs where available.