Description
WordPress Plugin TheCartPress eCommerce Shopping Cart is prone to a security bypass vulnerability because the application fails to properly check user credentials. An attacker can exploit this issue to obtain sensitive information which may help in launching further attacks. WordPress Plugin TheCartPress eCommerce Shopping Cart version 1.1.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.0 or latest
References
Related Vulnerabilities
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.31)
WordPress Plugin Advanced Ads-Ad Manager & AdSense Unspecified Vulnerability (1.7.1.1)
e107 Other Vulnerability (CVE-2006-3259)
WordPress Plugin WooCommerce EnvioPack Cross-Site Scripting (1.2)
WebLogic Improper Certificate Validation Vulnerability (CVE-2020-9488)